CVE-2021-27561: Yealink Device Management Server-Side Request Forgery (SSRF) Vulnerability
Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, without authentication.
Other sources
Yealink Device Management contains a server-side request forgery (SSRF) vulnerability that allows for unauthenticated remote code execution.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-27561?
CVE-2021-27561 is a vulnerability known as Yealink Device Management Server-Side Request Forgery (SSRF).
What is the severity of CVE-2021-27561?
The severity of CVE-2021-27561 is critical with a severity score of 9.8.
How does CVE-2021-27561 affect Yealink Device Management?
CVE-2021-27561 affects Yealink Device Management (DM) version 3.6.0.20 and allows command injection as root via the /sm/api/v1/firewall/zone/services URI without authentication.
How can I fix CVE-2021-27561?
To fix CVE-2021-27561, it is recommended to update Yealink Device Management to a version that is not affected by the vulnerability. Patching or upgrading the software is the best course of action.
Where can I find more information about CVE-2021-27561?
More information about CVE-2021-27561 can be found at the following link: [Yealink Device Management SSRF Vulnerability](https://ssd-disclosure.com/?p=4688)