CVE-2021-27561 | Yealink Device Management 3.6.0.20 services command injection
A vulnerability was found in Yealink Device Management 3.6.0.20 and classified as critical. Affected by this issue is some unknown functionality of the file /sm/api/v1/firewall/zone/services. The manipulation leads to command injection.
This vulnerability is handled as CVE-2021-27561. The attack needs to be initiated within the local network. Furthermore, there is an exploit available.