Trade-In Campaign – Upgrade to Yealink with Android 13 or Windows 11 + MDEP Online Webinar: Discover the Latest AI-Powered AV Solutions for Next-gen Digtial Workpace

Yealink IP Phone Directory Traversal Vulnerability





CVE Number: CVE-2020-24113

Published Date: August 22, 2022

Updated Date: September 4, 2023



Attention: 

Yealink places great importance on the security of our customers and products. This is a dynamic document and may be subject to updates. 




Vulnerability Summary

The Yealink W60B version 77.83.0.85 contains a directory traversal vulnerability in the contact file upload interface. Attackers can exploit this vulnerability to gain access to sensitive information and cause denial of service (DoS).




Influenced Products

The issue has been fixed in the iteration versions.

Product Family and Model                   

Affected Software Release           

Fixed Software Release             

SIP-CP935W

<=78.86.0.25

78.86.0.63

T3X Series Phones

<==124.86.0.40

124.86.0.60



The iteration versions do not have related issues.

Product Family and Model

Fixed Software Release

T5X Series Phones

96.86.0.70

T4XU Series Phones

108. 86.0.70

SIP-VP59

91.86.0.20

SIP-T58W

150.86.0.50

SIP-CP965

143.86.0.10

W70B

77.85.0.60

W80B

103.83.0.80

W90B

130.85.0.25



The discontinued version has been fixed.

Product Family and Model                   

Affected Software Release           

Fixed Software Release             

W60B

<= 77.83.0.85

77.85.0.25

SIP-CP920

<= 78.86.0.15

69.86.0.64

T4XS Series Phones

<= 66. 86.0.15

66.86.0.59

SIP-T58

No related issues

58.86.0.5

SIP-CP960

No related issues

73.86.0.5



Discontinued versions affected. Please contact Yealink Support technical personnel for resolution.

Product Family and Model                   

Affected Software Release           

Fixed Software Release             

SIP-T27P

45.83.0.120

End of maintenance 2018/2/1

SIP-T29G

46.83.0.120

End of maintenance 2021/3/31

SIP-T41P

36.83.0.120

End of maintenance 2020/4/1

SIP-T42G

29.83.0.120

End of maintenance 2020/4/1

SIP-T46G

28.83.0.120

End of maintenance 2020/4/1

SIP-T48G

35.83.0.120

End of maintenance 2020/4/1

SIP-T19P_E2

53.84.0.130

End of maintenance 2021/9/30

SIP-T21P_E2

52.84.0.130

End of maintenance 2021/9/30

SIP-T23G

44.84.0.130

End of maintenance 2021/9/30

SIP-T40P

54.84.0.130

End of maintenance 2021/9/30

SIP-T40G

76.84.0.130

End of maintenance 2021/9/30

SIP-T52S/T54S

70.84.0.80

End of maintenance 2019/3/31




Vulnerability Solution

Upgrade to the resolved version based on the affected version list. OEM users who are unsure whether the issue is resolved can inquire through Ticket or email Yealink Support technical personnel for feedback.




Resolution Measures

Yealink recommends all customers upgrade to the latest version.




Feedback

For any customers using affected systems who are concerned about this vulnerability in their deployment, please reach out to Yealink technical support for the latest information by visiting Yealink Support.

You can also find additional advanced security guidance and helpful content by searching in the Security News section of the Technical Support Center Yealink Support.



Your Privacy
Strictly Necessary Cookies
Preferences Cookies
Statistics Cookies
Targeted Cookies
PRIVACY PREFERENCE CENTER
When you visit any website, the website stores or retrieves information from your browser, mostly in the form of Cookies. This information may relate to your personal information, preferences or device information and is used primarily to enable the website to provide the services you expect. This information does not usually directly identify you personally, but can provide you with a more personalized web experience. We fully respect your privacy, so you can choose not to allow certain types of Cookies, simply by clicking on the name of a different Cookie category to learn more and change the default settings. However, blocking certain types of Cookies may affect your experience with the site and the services we can provide to you.
Learn more ->
Strictly Necessary Cookies
Always On
These Cookies are essential for users to navigate the site and use its features, which are necessary for the proper functioning of the site, and cannot be turned off on our system. They are set only for actions you do that are equivalent to service requests, such as setting up your login or populating a form.You can set your browser to block or alert you to such Cookies, but some features of the site will not work. These Cookies do not store any personally identifiable information.
Learn more ->
Preferences Cookies
These cookies are mainly used to record users' preferences while browsing the website and using its features. These cookies allow the website to remember your interactions with the website, choices you have made in the past and information you have entered, such as your preferred language or what your username and password are, so you can be logged in automatically. If you do not allow the use of such Cookies, you will not be able to enjoy a more convenient experience with the site.
Learn more ->
Statistics Cookies
These Cookies allow us to count the number of visits to our website and the sources of traffic in order to evaluate and improve the performance of our website. These Cookies also help us to understand the popularity of our pages and the activity of our visitors on the site. All information collected by such Cookies is aggregated to ensure that it remains anonymous. If you do not allow the use of such Cookies, we will have no way of knowing when you visit our site and will not be able to monitor site performance.
Learn more ->
Targeted Cookies
These Cookies may be set by our advertising partners through our website and may also be used by those companies to create profiles of your interests and to display relevant advertisements to you on other websites. These Cookies do not store personal information directly, but use some information that uniquely identifies your browser and Internet device. If you do not allow the use of such Cookies, the advertisements you see will be less targeted.
Learn more ->
PRIVACY PREFERENCE CENTER
Your Privacy
Your Privacy
When you visit any website, the website stores or retrieves information from your browser, mostly in the form of Cookies. This information may relate to your personal information, preferences or device information and is used primarily to enable the website to provide the services you expect. This information does not usually directly identify you personally, but can provide you with a more personalized web experience. We fully respect your privacy, so you can choose not to allow certain types of Cookies, simply by clicking on the name of a different Cookie category to learn more and change the default settings. However, blocking certain types of Cookies may affect your experience with the site and the services we can provide to you.
Learn more ->
Strictly Necessary Cookies
Strictly Necessary Cookies
Always On
These Cookies are essential for users to navigate the site and use its features, which are necessary for the proper functioning of the site, and cannot be turned off on our system. They are set only for actions you do that are equivalent to service requests, such as setting up your login or populating a form.You can set your browser to block or alert you to such Cookies, but some features of the site will not work. These Cookies do not store any personally identifiable information.
Learn more ->
Preferences Cookies
Preferences Cookies
These Cookies are primarily used to record the preferences of users as they navigate the site and use its features. These Cookies allow the website to remember the choices you have made in the past, such as which language you prefer or what your username and password are, so that you can automatically log in. If you do not allow the use of such Cookies, you will not be able to enjoy a more convenient experience with the site.
Learn more ->
Statistics Cookies
Statistics Cookies
These Cookies allow us to count the number of visits to our website and the sources of traffic in order to evaluate and improve the performance of our website. These Cookies also help us to understand the popularity of our pages and the activity of our visitors on the site. All information collected by such Cookies is aggregated to ensure that it remains anonymous. If you do not allow the use of such Cookies, we will have no way of knowing when you visit our site and will not be able to monitor site performance.
Learn more ->
Targeted Cookies
Targeted Cookies
These Cookies may be set by our advertising partners through our website and may also be used by those companies to create profiles of your interests and to display relevant advertisements to you on other websites. These Cookies do not store personal information directly, but use some information that uniquely identifies your browser and Internet device. If you do not allow the use of such Cookies, the advertisements you see will be less targeted.
Learn more ->
Except for necessary cookies, we may also use functional cookies (including third party cookies) to deliver experience for you. You can turn them off by clicking “configure". More information in cookies policy.
Configure I Accept