RULE(RULE ID:333638)

Rule General Information
Release Date: 2021-03-17
Rule Name: Yealink Remote Code Execution Vulnerability (CVE-2021-27561)
Severity:
CVE ID:
Rule Protection Details
Description: Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, without authentication.
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference: https://ssd-disclosure.com/ssd-advisory-yealink-dm-pre-auth-root-level-rce/
Solutions
Refer to the announcement or patch by the vendor: https://www.yealink.com/