PT-2024-20263 · Yealink · Yealink Meeting Server

Published

2024-02-08

·

Updated

2024-09-05

·

CVE-2024-24091

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Yealink Meeting Server versions prior to 26.0.0.66
Description The issue is related to an OS command injection vulnerability. This vulnerability can be exploited via the file upload interface.
Recommendations For versions prior to 26.0.0.66, update to version 26.0.0.66 or later to resolve the issue. As a temporary workaround, consider restricting access to the file upload interface until a patch is applied.

Fix

Code Injection

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2024-24091

Affected Products

Yealink Meeting Server