PT-2025-53601 · Yealink · Yealink T21P E2 Phone

Published

2025-12-26

·

Updated

2026-01-09

·

CVE-2025-66738

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Yealink T21P E2 Phone version 52.84.0.15
Description A flaw exists in the Yealink T21P E2 Phone that could allow a remote attacker with normal privileges to execute arbitrary code. This is possible through a crafted request targeting the ping function within the diagnostic component.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-16476
CVE-2025-66738

Affected Products

Yealink T21P E2 Phone