Cross Site Scripting Vulnerability in Yealink SIP-T21P E2 by Yealink
CVE-2025-14228
Key Information:
- Vendor
Yealink
- Status
- Vendor
- CVE Published:
- 8 December 2025
Badges
What is CVE-2025-14228?
A security flaw exists in the Yealink SIP-T21P E2 device, specifically within the Local Directory Page component, allowing cross site scripting (XSS) attacks. This vulnerability enables attackers to inject malicious scripts that can execute remotely, compromising user data and system integrity. The flaw affects devices that are no longer supported, as the vendor has not responded to prior disclosures regarding this issue. As the exploit is publicly available, it poses a significant risk to organizations using this obsolete product.
Affected Version(s)
SIP-T21P E2 52.84.0.15
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
