CVE-2024-24091: Yealink Meeting Server

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

Yealink Meeting Server before v26.0.0.66 was discovered to contain an OS command injection vulnerability via the file upload interface.

Affected products

  • Yealink Yealink Meeting Server: before 26.0.0.66 (fixed in 26.0.0.66)

Published 2024-02-08. Last modified 2026-06-17.