CVE-2024-24681: Yealink Configuration Encryption Tool

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

An issue was discovered in Yealink Configuration Encrypt Tool (AES version) and Yealink Configuration Encrypt Tool (RSA version before 1.2). There is a single hardcoded key (used to encrypt provisioning documents) across customers' installations.

Affected products

  • Yealink Configuration Encryption Tool: before 1.2 (fixed in 1.2); affected versions not specified

Published 2024-02-23. Last modified 2026-06-17.