Yealink Meeting Server 2X system command execution vulnerability
CVE Number: CVE- 2024-24091
Published Date: November 24, 2023
Updated Date: August 02, 2024
Vulnerability Summary
The Yealink Meeting Server file upload interface is vulnerable to OS command injection, allowing attackers to execute root-level commands by manipulating the file upload process.
Influenced Products
Product Family and Model | Affected | Fixed |
Yealink Meeting Server | < V26.0.0.66 | V26.0.0.66 |
Vulnerability Solution
Yealink has released a software update to address the vulnerabilities in versions earlier than 26.0.0.66. Please update promptly.
Resolution Measures
Yealink recommends all customers upgrade to the latest version.
Acknowledgments
We sincerely thank the Positive Technologies team for their professional support in addressing this security issue.
Feedback
For any customers using affected systems who are concerned about this vulnerability in their deployment, please reach out to Yealink technical support for the latest information by visiting Yealink Support.
You can also find additional advanced security guidance and helpful content by searching in the Security News section of the Technical Support Center Yealink Support.