RSA Key Pair in Yealink Config Encrypt Tool May Leave System Vulnerable to Decryption
CVE-2022-48625
Currently unrated
What is CVE-2022-48625?
The Yealink Config Encrypt Tool, prior to version 1.2, contains a significant vulnerability related to its hardcoded RSA key pair. This flaw allows potential attackers to exploit the built-in encryption mechanisms, posing a risk of unauthorized decryption of sensitive data. The existence of a static encryption key undermines the integrity and confidentiality of information processed by the tool, raising critical security concerns for users relying on this software for secure communications.
References
Timeline
Vulnerability published