LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-27561: Yealink Device Management Server-Side Request Forgery (SSRF) Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Nov 17, 2021
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-27561 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of Nov 17, 2021 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Yealink Device Management contains a server-side request forgery (SSRF) vulnerability that allows for unauthenticated remote code execution.

CVE-2021-27561 is a server-side request forgery (SSRF) vulnerability in Yealink Device Management that can lead to unauthenticated remote code execution. For IT and security teams running this management platform, the issue matters because an unauthenticated attacker who can reach the service may abuse it to execute code on the host, potentially compromising device fleets and adjacent infrastructure.

Public detail is limited to the CISA description and the listed weakness; confirm exact scope, fixed builds, and deployment notes against the vendor advisory before acting.

How it works

The vulnerability is characterized as server-side request forgery (SSRF) in Yealink Device Management and is associated with CWE-78. In an SSRF flaw of this class, the application can be induced to make outbound requests or perform actions on behalf of an attacker. When that capability is chained to insufficient input handling, it can result in unauthenticated remote code execution on the management server itself.

An attacker who can reach the exposed management interface does not need valid credentials. They abuse the SSRF behavior to cause the server to interact with internal resources or to trigger command execution paths. Exact request formats, parameters, and exploit mechanics are not provided in the available facts; treat any public proof-of-concept claims cautiously and validate behavior only in a controlled lab against the vendor’s description.

Am I affected? How to find it in your systems

Yealink Device Management is typically deployed as a central server or appliance used to provision, configure, and monitor Yealink endpoints (phones, related collaboration devices). It often runs on internal networks or in DMZ/management segments and may be reachable over HTTP/HTTPS from administrator workstations or broader corporate networks.

How to remediate

Patch first. Apply the updates issued by Yealink for Device Management exactly as described in the vendor advisory and follow CISA’s required action: apply updates per vendor instructions. After patching, verify the service version and restart or redeploy components as directed.

If you can't patch immediately

Reduce exposure until the vendor update can be applied.

If your data may have been exposed

Actively exploited vulnerabilities of this type can lead to full compromise of the management server and subsequent access to device configurations, credentials, or connected systems. Known ransomware use is not documented for this CVE. If you suspect exploitation, isolate the host, preserve logs and memory images, rotate any credentials stored on or used by the platform, and follow your incident-response plan. You can also run a free exposure scan of your email addresses against known breach data to check whether associated accounts appear in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedYealink · Device Management
WeaknessCWE-78
Added to CISA KEVNov 3, 2021
Federal patch deadlineNov 17, 2021
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities