CyberRota Analysis
AI-GeneratedYealink SIP-T33G devices running firmware versions prior to 124.87.0.0 are vulnerable to a race condition that allows authenticated attackers to disrupt active diagnostic processes by deleting output files in the diagnostic directory. This can lead to system instability and inconsistent states during critical operations like traceroute or ping. Organizations using these devices should prioritize patching to mitigate potential disruptions and maintain system integrity.
Original NVD Description
Yealink SIP-T33G firmware versions 124.86.x.x prior to 124.87.0.0 contain a race condition vulnerability that allows authenticated attackers to interrupt active diagnostic processes by concurrently deleting output files written to predictable paths under the diagnostic directory. Attackers can trigger a diagnostic operation such as traceroute or ping and simultaneously invoke the file deletion endpoint to terminate the running process, leaving the system in an inconsistent state.