CVE-2021-27561KEV · OVERDUE

Yealink Device Management Server-Side Request Forgery (SSRF) Vulnerability

Critical · published October 15, 2021

Patch now

Confirmed exploited, and the score agrees

CVSS calls it critical at 9.8. It is confirmed in active exploitation. It sits in the 99.6th percentile for exploit probability.

1754
days past CISA
deadline
CVSS v3.1
9.8
EPSS
83%
Percentile
99.6
In the wild
Confirmed
What it is

🚨 A command injection flaw in Yealink Device Management means attackers can run commands as root without breaking a sweat! 🔥 Think of it like a hotel manager who lets anyone stroll through the backdoor without checking credentials — suddenly, guests can access the staff-only areas and cause mayhem! With this vulnerability, an attacker could execute arbitrary commands on the device, potentially taking full control. Imagine an intruder not just snooping around but also changing settings, disrupting services, or even launching further attacks on your network. It’s a recipe for chaos!

Put simply

Think of it like a hotel manager who lets anyone stroll through the backdoor without checking credentials — suddenly, guests can access the staff-only areas and cause mayhem! CVE-2021-27561 allows for command injection via the /sm/api/v1/firewall/zone/services endpoint without any authentication check, enabling attackers to gain root access and execute arbitrary commands.

What to do

With this vulnerability, an attacker could execute arbitrary commands on the device, potentially taking full control. Imagine an intruder not just snooping around but also changing settings, disrupting services, or even launching further attacks on your network. It’s a recipe for chaos! Immediate action is essential: patch your Yealink Device Management to version 3.6.0.21 or later. Additionally, restrict access to the affected endpoint and consider implementing additional security measures such as firewalls or intrusion detection systems. You’ve got this! Act fast, and you’ll have your defenses reinforced in no time! 🛡️

The record
Technical detail
CVSS v3.1
9.8 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.82865 · 99.6th percentile
Published
2021-10-15T17:11Z
KEV added
2021-11-03 · due 2021-11-17
EPSS history
Timeline
  • 03 NOV 00:00Z
    Added to CISA KEV — remediate by Nov 17
    kev
  • 15 OCT 17:11Z
    Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, without authentication
    cvelistv5