SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-7208

MEDIUM · CVSS 5.3

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

Yealink SIP-T33G devices running firmware versions prior to 124.87.0.0 are vulnerable to a race condition that allows authenticated attackers to disrupt active diagnostic processes by deleting output files in the diagnostic directory. This can lead to system instability and inconsistent states during critical operations like traceroute or ping. Organizations using these devices should prioritize patching to mitigate potential disruptions and maintain system integrity.

CVE
CVE-2026-7208
Severity
MEDIUM
CVSS
5.3
EPSS
N/A

Original NVD Description

Yealink SIP-T33G firmware versions 124.86.x.x prior to 124.87.0.0 contain a race condition vulnerability that allows authenticated attackers to interrupt active diagnostic processes by concurrently deleting output files written to predictable paths under the diagnostic directory. Attackers can trigger a diagnostic operation such as traceroute or ping and simultaneously invoke the file deletion endpoint to terminate the running process, leaving the system in an inconsistent state.