漏洞描述
Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, without authentication.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
ssd-disclosure.comhttps://ssd-disclosure.com/ssd-advisory-yealink-dm-pre-auth-root-level-rce/↗cve.mitre.orghttps://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-27561↗ssd-disclosure.comhttps://ssd-disclosure.com/?p=4688↗github.comhttps://github.com/ARPSyndicate/cvemon↗github.comhttps://github.com/ARPSyndicate/kenzer-templates↗