Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-7208— Yealink SIP-T33G < 124.87.0.0 Race Condition via Diagnostic File Deletion

Quick assessment

Affected
Yealink SIP-T33G
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Yealink SIP-T33G 固件版本 124.86.x.x(124.87.0.0 之前)存在一个竞态条件漏洞。经过认证的(authenticated)攻击者可以通过并发删除写入到诊断目录下可预测路径中的输出文件,从而中断正在运行的诊断进程。攻击者可以触发一项诊断操作(如 traceroute 或 ping),同时调用文件删除接口来终止正在运行的进程,导致系统处于不一致的状态。

CVSS 5.3 · Medium

Affected Version Matrix 1

VendorProduct Version RangeStatus
Yealink SIP-T33G 124.86.0.0< 124.87.0.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-7208

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Yealink SIP-T33G < 124.87.0.0 Race Condition via Diagnostic File Deletion
Source: CVE Program / CVE List V5
Vulnerability Description
Yealink SIP-T33G firmware versions 124.86.x.x prior to 124.87.0.0 contain a race condition vulnerability that allows authenticated attackers to interrupt active diagnostic processes by concurrently deleting output files written to predictable paths under the diagnostic directory. Attackers can trigger a diagnostic operation such as traceroute or ping and simultaneously invoke the file deletion endpoint to terminate the running process, leaving the system in an inconsistent state.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
使用共享资源的并发执行不恰当同步问题(竞争条件)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Yealink SIP-T33G 124.86.0.0 ~ 124.87.0.0 -

II. Public POCs for CVE-2026-7208

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-7208

登录查看更多情报信息。

Vendor Advisories for CVE-2026-7208 (1)

Vendor Pages for CVE-2026-7208 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-7208

No comments yet


Leave a comment