CVE-2025-68644: High severity Yealink RPS vulnerability
Yealink RPS before 2025-06-27 allows unauthorized access to information, including AutoP URL addresses. This was fixed by deploying an enhanced authentication mechanism through a security update to all cloud instances.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-68644?
CVE-2025-68644 has been classified as a high-severity vulnerability due to the potential for unauthorized access to sensitive information.
How do I fix CVE-2025-68644?
To fix CVE-2025-68644, update the Yealink RPS to the version released after June 27, 2025, which implements an enhanced authentication mechanism.
What type of information is exposed by CVE-2025-68644?
CVE-2025-68644 allows unauthorized access to sensitive information, including AutoP URL addresses.
Which versions of Yealink RPS are affected by CVE-2025-68644?
All versions of Yealink RPS prior to the security update on June 27, 2025, are affected by CVE-2025-68644.
Is there a workaround for CVE-2025-68644?
There is no official workaround for CVE-2025-68644; the recommended action is to update to the fixed version as soon as possible.