PT-2025-52578 · Yealink · Yealink Rps

Published

2025-12-21

·

Updated

2025-12-26

·

CVE-2025-68644

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Yealink RPS versions prior to 2025-06-27
Description The Yealink RPS software contains a flaw that allows unauthorized access to information, including AutoP URL addresses. The issue was addressed by implementing a more robust authentication process through a security update applied to all cloud instances.
Recommendations Update Yealink RPS to version 2025-06-27 or later.

Fix

Authentication Bypass by Spoofing

Weakness Enumeration

Related Identifiers

CVE-2025-68644

Affected Products

Yealink Rps