SB2025080855 - Multiple vulnerabilities in Yealink IP Phones and RPS (Redirect and Provisioning Service)
Published: August 8, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 4 secuirty vulnerabilities.
1) Improper Restriction of Excessive Authentication Attempts (CVE-ID: CVE-2025-52916)
The vulnerability allows a remote user to compromise the target system.
The vulnerability exists due to improper restriction of excessive authentication attempts. A remote administrator can conduct brute force attacks to gain access to sensitive information.
2) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2025-52917)
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to improper restriction of excessive authentication attempts. A remote user can gain access to sensitive information.
3) Incorrect User Management (CVE-ID: CVE-2025-52918)
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the affected products fail to enforce access restrictions on OpenAPIs for frozen enterprise accounts. A remote user can gain access to deactivated interfaces.
4) Improper Certificate Validation (CVE-ID: CVE-2025-52919)
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the certificate upload function in the affected products does not properly validate certificate content. A remote user can upload invalid certificates on the system.
Remediation
Install update from vendor's website.
References
- https://dnip.ch/2025/06/25/yealink-voip-phones-insecurity-by-design/
- https://seclists.org/fulldisclosure/2025/Jun/20
- https://support.yealink.com/en/portal/knowledge/show?id=6476e7cd6a27da76bd06a9c9
- https://www.yealink.com/en/trust-center/security-advisories/b8dc062eaa8d4f59
- https://www.cisa.gov/news-events/ics-advisories/icsa-25-219-08
- https://www.yealink.com/en/trust-center/security-advisories/f8205560a8c7443f
- https://support.yealink.com/en/portal/knowledge/show?id=646b44278ef325311f38303f
- https://www.yealink.com/en/trust-center/security-advisories/1318c5efb82e4526
- https://www.yealink.com/en/trust-center/security-advisories/ecb16a4993014d22