Back to Database
Status published
Medium
CVE-2025-52918
Yealink RPS before 2025-05-26 does not prevent OpenAPI access by...
Vulnerability Description
Yealink RPS before 2025-05-26 does not prevent OpenAPI access by frozen enterprise accounts, allowing unauthorized access to deactivated interfaces.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-52918
Credits & Attribution
No credits recorded in the NVD database.
References
More from Yealink
View All →CVE-2025-68644
Yealink RPS before 2025-06-27 allows unauthorized access to information, including...
High
7.4
CVE-2025-52919
In Yealink RPS before 2025-05-26, the certificate upload function does...
Medium
4.3
CVE-2025-52917
The Yealink RPS API before 2025-05-26 lacks rate limiting, potentially...
Medium
4.3
CVE-2025-52916
Yealink RPS before 2025-06-04 lacks SN verification attempt limits, enabling...
Low
2.2
CVE-2025-14228
Yealink SIP-T21P E2 Local Directory cross site scripting
Medium
5.1
Affected Vendor
Yealink
View all reports →Affected Software
RPS
Vulnerable Versions:
0
Timeline
Official Publish:
June 21st, 2025
Last Modified:
July 28th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N