DATE PUBLISHED: 2023-11-24
DATE UPDATED: 2024-04-01
Vulnerability Summary
The front-end JS file of the Yealink Meeting Server contains encryption methods and encryption keys. Attackers can obtain static key information from the JS file and successfully decrypt the plaintext password based on the obtained key information.
Product Affected
Product Family and Model | Affected | Fixed |
Yealink Meeting Server | < V26.0.0.67 | V26.0.0.67 |
Vulnerability Solution
Yealink has released a software update to address the vulnerabilities in versions earlier than 26.0.0.67. Please update promptly.
Resolution Measures
Yealink recommends all customers to upgrade to the latest version.
Acknowledgments
We sincerely thank the Positive Technologies team for their professional support in addressing this security issue.
Contact
Any customer using an affected system who is concerned about this vulnerability within their deployment should contact Yealink Technical Support by visiting: https://support.yealink.com/en/portal/home for the latest information.
You might also find value in the high-level security guidance and security news located at: https://support.yealink.com/en/portal/home.