VendorsYealinkyealink_meeting_serverall versions
Vulnerabilities

Yealink Meeting Server (YMS)

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2024-24091
Yealink Meeting Server before v26.0.0.66 was discovered to contain an OS command injection vulnerability via the file upload interface.
Published 2024-02-08 · Modified
9.8EPSS 0.011
CVE-2024-48352
Yealink Meeting Server before V26.0.0.67 is vulnerable to sensitive data exposure in the server response via sending HTTP request with enterprise ID.
Published 2024-11-01 · Modified
7.5EPSS 0.005
CVE-2024-48353
Yealink Meeting Server before V26.0.0.67 allows attackers to obtain static key information from a front-end JS file and decrypt the plaintext passwords based on the obtained key information.
Published 2024-11-01 · Modified
7.5EPSS 0.004