Yealink Vulnerabilities and Affected Products
Vulnerabilities associated with SIP-T21P E2.
Products
Clear product- SIP-T46U6 vulnerabilities
- RPS5 vulnerabilities
- meeting_server3 vulnerabilities
- yealink_vp59_firmware3 vulnerabilities
- config_encrypt_tool_add_rsa1 vulnerability
- Device Management1 vulnerability
- MeetingBar A301 vulnerability
- sip-t19p-e2_firmware1 vulnerability
- SIP-T21P E21 vulnerability
- sip-t38g1 vulnerability
- w60b1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-14228MEDIUM | Yealink SIP-T21P E2 Local Directory cross site scriptingA weakness has been identified in Yealink SIP-T21P E2 52.84.0.15. Impacted is an unknown function of the component Local Directory Page. This manipulation causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way. This vulnerability only affects products that are no longer supported by the maintainer. | CVSS5.1v4.0 | EPSS0.227% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |