CISA Vulnerability Report: ICSA-25-219-08 Yealink IP Phones and RPS (Redirect and Provisioning Service)

skillsinc

Customer
Joined
Jun 8, 2009
Messages
18
Reaction score
1
CISA is reporting this Yealink Vulnerability: Improper Restriction of Excessive Authentication Attempts, Allocation of Resources Without Limits or Throttling, Incorrect Authorization, Improper Certificate Validation

https://www.cisa.gov/news-events/ics-advisories/icsa-25-219-08

Any idea when we might get the latest firmware updates to mitigate this vulnerability?


3.1 AFFECTED PRODUCTS​

The following versions of Yealink IP products are affected:

  • SIP-T19P_E2: Versions prior to 53.84.0.121
  • SIP-T21P_E2: Versions prior to 52.84.0.121
  • SIP-T23G: Versions prior to 44.84.0.121
  • SIP-T40G: Versions prior to 76.84.0.121
  • SIP-T40P: Versions prior to 54.84.0.121
  • SIP-T27G: Versions prior to 69.84.0.121
  • SIP-T41S: Versions prior to 66.84.0.121
  • SIP-T42S: Versions prior to 66.84.0.121
  • SIP-T46S: Versions prior to 66.84.0.121
  • SIP- T48S: Versions prior to 66.84.0.121
  • SIP-CP920: Versions prior to 78.84.0.121
  • SIP-T53: Versions prior to X.84.0.121
  • SIP-T53W: Versions prior to X.84.0.121
  • SIP-T54W: Versions prior to X.84.0.121
  • SIP-T57W: Versions prior to X.84.0.121
  • SIP-T56A: Versions prior to 58.84.0.37
  • SIP-T58: Versions prior to 58.84.0.37
  • W52P: Versions prior to 25.81.0.67
  • W60B: Versions prior to 77.83.0.83
  • CP960: Versions prior to 73.84.0.37
  • SIP-T27P: Version 45.83.0.160 and prior
  • SIP-T29G: Version 46.83.0.160 and prior
  • SIP-T41P: Version 36.83.0.160 and prior
  • SIP-T42G: Version 29.83.0.160 and prior
  • SIP-T46G: Version 28.83.0.160 and prior
  • SIP-T48G: Version 35.83.0.160 and prior
  • SIP-T20P: All versions
  • SIP-T22P: All versions
  • SIP-T26P: All versions
  • SIP-T27P: All versions
  • T52S: All versions
  • T54S: All versions
  • RPS (Redirect and Provisioning Service): All builds prior to 05-26-2025
 
  • Like
Reactions: stumac
Hello skillsinc,

Thank you for raising the CISA report regarding vulnerabilities in Yealink’s devices firmware and provisioning infrastructure.

To clarify, these are vendor-side issues rooted in Yealink’s own design and certificate practices, which lie entirely outside 3CX's control.

Regarding affected devices:
  • For supported Yealink models (T23G, T53, T53W, T54W, T57W), the firmware versions currently deployed via 3CX are not impacted.
  • All others models identified in the report are legacy/EOL, we’ve already contacted Yealink multiple times to request validated firmwares. While no updated images have been provided yet, we’re monitoring the situation and will reassess support for those models as needed. Please note that for EOL hardware, firmware is only deployed if a vendor explicitly provides and requests integration. A simple mitigation here is to use 3CX Apps instead of these devices.

Regarding Yealink RPS, 3CX has already safeguards to mitigate exposure :
  • The PBX sends provisioning instructions only to the 3CX RPS gateway, not directly to Yealink — this intermediary model gives us tighter oversight.
  • Provisioning URLs are secured by short-lived, one-time credentials, which auto-expire after successful use or if unused.
  • The 3CX RPS gateway also performs automated cleanup of records on Yealink’s RPS, ensuring no stale credentials remain (unlike many PBX vendors).
  • All provisioning actions are logged with timestamps and source IPs, and are subject to the same blacklist/whitelist enforcement as all other inbound PBX traffic.

In short, we recommend all the community contacting Yealink directly for device-level mitigations and firmware status so they address this matter with priority and provide us with new firmware in a timely manner. Meanwhile, 3CX’s provisioning design and control layers significantly reduce the practical risk of exploitation — based on deliberate architectural decisions made well before this disclosure.

We remain at your disposal for any further assistance.
 

Members Online Now

No members online now.

Forum statistics

Threads
111,831
Messages
589,277
Members
164,660
Latest member
RJenkinsROCK