CVE-2025-66738: Command Injection
Published Dec 26, 2025
·Updated
An issue in Yealink T21PE2 Phone 52.84.0.15 allows a remote normal privileged attacker to execute arbitrary code via a crafted request the ping function of the diagnostic component.
Affected Software
3 affected components
Yealink T21P_E2 Phone
All of the following
Yealink Sip-t21\(p\)e2 Firmware=52.84.0.15
Yealink Sip-t21\(p\)e2
Event History
Dec 26, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-66738?
CVE-2025-66738 is considered a critical vulnerability due to its ability to allow remote code execution.
2
How do I fix CVE-2025-66738?
To fix CVE-2025-66738, update your Yealink T21P_E2 Phone to the latest firmware version provided by Yealink.
3
Who is affected by CVE-2025-66738?
Users of the Yealink T21P_E2 Phone running firmware version 52.84.0.15 are affected by CVE-2025-66738.
4
What is the exploitation vector for CVE-2025-66738?
CVE-2025-66738 can be exploited by an attacker sending crafted requests to the ping function of the phone's diagnostic component.
5
What impact does CVE-2025-66738 have on the device?
Exploiting CVE-2025-66738 allows an attacker to execute arbitrary code, potentially leading to complete system compromise.