Loading
Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, without authentication.
Use CWE-78, Yealink vendor hub and Device Management product page to widen CVE-2021-27561 into its surrounding weakness, vendor, and product context.