CVE-2025-68644: Yealink Rps
High severity, CVSS 7.4. EPSS: 0.3% chance of exploitation in the next 30 days.
Yealink RPS before 2025-06-27 allows unauthorized access to information, including AutoP URL addresses. This was fixed by deploying an enhanced authentication mechanism through a security update to all cloud instances.
Affected products
- Yealink Rps: before 2025-06-27 (fixed in 2025-06-27)
Published 2025-12-21. Last modified 2026-06-17.