CVE-2024-48353: Yealink Meeting Server
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Yealink Meeting Server before V26.0.0.67 allows attackers to obtain static key information from a front-end JS file and decrypt the plaintext passwords based on the obtained key information.
Affected products
- Yealink Yealink Meeting Server: before 26.0.0.67 (fixed in 26.0.0.67)
Published 2024-11-01. Last modified 2026-06-17.