CVE List

CVE-2025-66738

Critical 8.8

An issue in Yealink T21P_E2 Phone 52.84.0.15 allows a remote normal privileged attacker to execute arbitrary code via a crafted request the ping function of the diagnostic component.

Published December 26, 2025.

Affected software

Get alerts for Yealink Sip-t21\(p\)e2 Firmware

Reference links