CVE-2025-52917: Medium severity Yealink RPS API vulnerability
Published Jun 21, 2025
·Updated
The Yealink RPS API before 2025-05-26 lacks rate limiting, potentially enabling information disclosure via excessive requests.
Affected Software
1 affected component
Yealink RPS API<2025-05-26
Event History
Jun 21, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-52917?
CVE-2025-52917 is rated as a high severity vulnerability due to the lack of rate limiting in the Yealink YMCS RPS API.
2
How do I fix CVE-2025-52917?
To mitigate CVE-2025-52917, update the Yealink YMCS RPS API to version 2025-05-26 or later.
3
What risks are associated with CVE-2025-52917?
CVE-2025-52917 can lead to information disclosure as attackers may exploit the vulnerability through excessive requests.
4
Which versions of Yealink YMCS RPS API are affected by CVE-2025-52917?
CVE-2025-52917 affects all versions of the Yealink YMCS RPS API prior to 2025-05-26.
5
Is CVE-2025-52917 related to denial of service attacks?
While CVE-2025-52917 primarily concerns information disclosure, excessive requests could also impact the availability of the service.