CyberSec.Space Logo
返回 CVE 浏览器

CVE-2021-27561

🔥 Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
EPSS Score73.6050%
EPSS Percentile95.53th
Published2021-10-15
Last Modified2025-11-10
Data SourcesNVDCISA KEVFIRST.org EPSS

Vulnerability Description

Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, without authentication.

Affected Platforms (CPE)

📦
Yealink

Device Management

<= 3.6.0.20

References & Advisories

相关漏洞威胁