Record summary

CVE-2026-1735 has a selected CVSS score of 2.4 (low).

Description

A weakness has been identified in Yealink MeetingBar A30 133.321.0.3. This issue affects some unknown processing of the component Diagnostic Handler. This manipulation causes command injection. It is feasible to perform the attack on the physical device. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 2, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List133.321.0.3affected

References

5