Vulnerability Description
Yealink RPS before 2025-05-26 does not prevent OpenAPI access by frozen enterprise accounts, allowing unauthorized access to deactivated interfaces.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://dnip.ch/2025/06/25/yealink-voip-phones-insecurity-by-design/
- https://seclists.org/fulldisclosure/2025/Jun/20
- https://support.yealink.com/en/portal/knowledge/show?id=646b44278ef325311f38303f
- https://www.yealink.com/en/trust-center/security-advisories/1318c5efb82e4526
FAQ
What is CVE-2025-52918?
CVE-2025-52918 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Yealink RPS before 2025-05-26 does not prevent OpenAPI access by frozen enterprise accounts, allowing unauthorized access to deactivated interfaces.
How severe is CVE-2025-52918?
CVE-2025-52918 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-52918?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.