Race Condition Vulnerability in Yealink SIP-T33G IP Phone
CVE-2026-7208

6MEDIUM

Key Information:

Vendor

Yealink

Status
Vendor
CVE Published:
14 September 2026

What is CVE-2026-7208?

The Yealink SIP-T33G IP Phone contains a race condition vulnerability within its firmware versions 124.86.x.x and older. This flaw allows authenticated attackers to disrupt ongoing diagnostic operations by deleting output files from expected paths in the diagnostic directory. When attackers execute a diagnostic command, such as a traceroute, concurrent file deletions can terminate the process prematurely, resulting in unpredictable system behavior and potential inconsistencies within the device.

Affected Version(s)

SIP-T33G 124.86.0.0 < 124.87.0.0

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jean-Marie Bourbon of Bourbon Offensive Security Services
VulnCheck
.