CVE Number: CVE-2025-52918
DATE PUBLISHED: 2025-06-10
DATE UPDATED: 2025-07-11
Please Note:
Yealink takes the security of our customers and our products seriously. This is a living document and may be subject to updates.
Vulnerability Summary
Yealink RPS fails to enforce access restrictions on OpenAPIs for frozen enterprise accounts, allowing unauthorized access to deactivated interfaces
Vulnerability CVSS
CVSS Severity: MEDIUM
CVSS Score: 5.0
CVSS Vector String: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Product Affected
Product Family and Model | Affected | Fixed |
RPS | Prior to 2025-05-26 | Patched on 2025-05-26 |
Resolution Measures
Yealink has implemented access restrictions on frozen enterprise OpenAPIs to prevent unauthorized invocation.Yealink released a security update on May 26, 2025, which has been automatically deployed to all cloud service instances.
References
https://nvd.nist.gov/vuln/detail/CVE-2025-52918
Feedback
For any customers using affected systems who are concerned about this vulnerability in their deployment, please reach out to Yealink technical support for the latest information by visiting Yealink Support. You can also find additional advanced security guidance and helpful content by searching in the Security News section of the Technical Support Center Yealink Support.