CVE-2025-52916: Low severity Yealink RPS vulnerability
Published Jun 21, 2025
·Updated
Yealink RPS before 2025-06-04 lacks SN verification attempt limits, enabling brute-force enumeration (last five digits).
Affected Software
1 affected component
Yealink RPS<2025-06-04
Event History
Jun 21, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeakness
Jul 18, 57452
Event
via FIRST·02:28 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-52916?
CVE-2025-52916 has been classified as a medium severity vulnerability due to its potential for brute-force enumeration.
2
How do I fix CVE-2025-52916?
To fix CVE-2025-52916, update Yealink YMCS RPS software to a version released after June 4, 2025.
3
What type of attacks are possible with CVE-2025-52916?
CVE-2025-52916 allows attackers to perform brute-force attacks to enumerate the last five digits of some accounts.
4
Which versions of Yealink YMCS RPS are affected by CVE-2025-52916?
Yealink YMCS RPS versions prior to 2025-06-04 are affected by CVE-2025-52916.
5
Is there a workaround for CVE-2025-52916?
Currently, there are no documented workarounds for CVE-2025-52916; updating the software is the recommended solution.