Vulnerabilities > Yealink > Yealink Meeting Server

DATE CVE VULNERABILITY TITLE RISK
2024-11-01 CVE-2024-48353 Insecure Storage of Sensitive Information vulnerability in Yealink Meeting Server
Yealink Meeting Server before V26.0.0.67 allows attackers to obtain static key information from a front-end JS file and decrypt the plaintext passwords based on the obtained key information.
network
low complexity
yealink CWE-922
7.5
2024-11-01 CVE-2024-48352 Unspecified vulnerability in Yealink Meeting Server
Yealink Meeting Server before V26.0.0.67 is vulnerable to sensitive data exposure in the server response via sending HTTP request with enterprise ID.
network
low complexity
yealink
7.5
2024-02-08 CVE-2024-24091 OS Command Injection vulnerability in Yealink Meeting Server
Yealink Meeting Server before v26.0.0.66 was discovered to contain an OS command injection vulnerability via the file upload interface.
network
low complexity
yealink CWE-78
critical
9.8