CVE-2025-68644: Yealink Rps

High severity, CVSS 7.4. EPSS: 0.3% chance of exploitation in the next 30 days.

Yealink RPS before 2025-06-27 allows unauthorized access to information, including AutoP URL addresses. This was fixed by deploying an enhanced authentication mechanism through a security update to all cloud instances.

Affected products

  • Yealink Rps: before 2025-06-27 (fixed in 2025-06-27)

Published 2025-12-21. Last modified 2026-06-17.