CVE-2025-52919: Medium severity Yealink RPS vulnerability
In Yealink RPS before 2025-05-26, the certificate upload function does not properly validate certificate content, potentially allowing invalid certificates to be uploaded.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52919?
CVE-2025-52919 is classified as a medium severity vulnerability due to the potential for invalid certificate uploads.
How do I fix CVE-2025-52919?
To fix CVE-2025-52919, update to the Yealink YMCS RPS version released after May 26, 2025, which addresses the certificate validation issue.
What impact does CVE-2025-52919 have on Yealink YMCS RPS?
CVE-2025-52919 allows for the upload of invalid certificates, which could compromise the security of the device by enabling unauthorized access.
Is CVE-2025-52919 being actively exploited?
There is currently no public indication that CVE-2025-52919 is actively being exploited in the wild.
What versions of Yealink YMCS RPS are affected by CVE-2025-52919?
All versions of Yealink YMCS RPS prior to 2025-05-26 are affected by CVE-2025-52919.