drive.google.comexploit
https://drive.google.com/file/d/1Uf46ihr8UmeXsFfkcvAeOtF1TkvGjozy/view?usp=sharing CVE-2026-1735
LOW
Yealink MeetingBar A30 Diagnostic command injection
Record summary
CVE-2026-1735 has a selected CVSS score of 2.4 (low).
Description
A weakness has been identified in Yealink MeetingBar A30 133.321.0.3. This issue affects some unknown processing of the component Diagnostic Handler. This manipulation causes command injection. It is feasible to perform the attack on the physical device. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 2, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
MeetingBar A30Browse Yealink / MeetingBar A30 | CVE List | 133.321.0.3 | affected |
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-1735 VDB-343634 | CTI Indicators (IOB, IOC, TTP)signaturepermissions required
https://vuldb.com/?ctiid.343634 VDB-343634 | Yealink MeetingBar A30 Diagnostic command injectionvdb entry
https://vuldb.com/?id.343634 Submit #736622 | Yealink MeetingBar A30 133.321.0.3 Command InjectionThird-party advisory
https://vuldb.com/?submit.736622