Directory Traversal Vulnerability in Yealink T21P_E2 Phone
CVE-2025-66737
6.5MEDIUM
What is CVE-2025-66737?
The Yealink T21P_E2 Phone version 52.84.0.15 exhibits a significant Directory Traversal vulnerability. This issue allows an authenticated attacker with normal privileges to exploit a flaw in the diagnostic component's read function, enabling them to read arbitrary files on the device. As a result, sensitive information may be accessed, posing potential security risks. Organizations utilizing this product should take immediate steps to mitigate any risks associated with this vulnerability.
