First published: Thu Feb 08 2024(Updated: )
Yealink Meeting Server before v26.0.0.66 was discovered to contain an OS command injection vulnerability via the file upload interface.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Yealink Meeting Server | <26.0.0.66 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-24091 is rated as a high severity vulnerability due to its potential for OS command injection.
To fix CVE-2024-24091, users should update Yealink Meeting Server to version 26.0.0.66 or later.
CVE-2024-24091 affects all versions of Yealink Meeting Server prior to 26.0.0.66.
CVE-2024-24091 is an OS command injection vulnerability that can be exploited via the file upload interface.
CVE-2024-24091 was disclosed as a vulnerability prior to the release of the fixed version on Yealink's official channels.