CVE-2025-66737: Medium severity Yealink T21P_E2 Phone vulnerability
Published Dec 26, 2025
·Updated
Yealink T21PE2 Phone 52.84.0.15 is vulnerable to Directory Traversal. A remote normal privileged attacker can read arbitrary files via a crafted request result read function of the diagnostic component.
Affected Software
3 affected components
Yealink T21P_E2 Phone
All of the following
Yealink Sip-t21\(p\)e2 Firmware=52.84.0.15
Yealink Sip-t21\(p\)e2
Event History
Dec 26, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-66737?
CVE-2025-66737 has been classified as a moderate severity vulnerability due to its potential to expose sensitive files.
2
What type of attack is associated with CVE-2025-66737?
CVE-2025-66737 is associated with a remote directory traversal attack that allows arbitrary file reading.
3
Who is affected by CVE-2025-66737?
The vulnerability affects users of the Yealink T21P_E2 Phone running version 52.84.0.15.
4
How do I fix CVE-2025-66737?
To mitigate CVE-2025-66737, update your Yealink T21P_E2 Phone to the latest firmware that addresses this vulnerability.
5
Can CVE-2025-66737 be exploited remotely?
Yes, CVE-2025-66737 can be exploited remotely by normal privileged attackers through crafted requests.