ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Yealink security hole

    IT Discussion
    security yealink voip
    3
    8
    2.5k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • JaredBuschJ
      JaredBusch
      last edited by JaredBusch

      Was checking Google to see if there was a way to telnet into a Yealink phone because I am having a hell of a time with the VPN config on a phone in Cabo.

      Found this: http://blog.danielparnell.com/?p=217
      Did a little digging and did not see any news on an update or fix.

      Imgur

      1 Reply Last reply Reply Quote 2
      • scottalanmillerS
        scottalanmiller
        last edited by

        A backdoor in a Chinese phone! Not really surprised.

        1 Reply Last reply Reply Quote 0
        • JaredBuschJ
          JaredBusch
          last edited by

          Country of origin is not relevant.

          The exact same thing is found in most embedded devices.

          scottalanmillerS 1 Reply Last reply Reply Quote 0
          • scottalanmillerS
            scottalanmiller @JaredBusch
            last edited by

            @JaredBusch said:

            Country of origin is not relevant.

            The exact same thing is found in most embedded devices.

            That's because most embedded devices come from either China or the US. The exact two countries you would expect.

            1 Reply Last reply Reply Quote 0
            • DominicaD
              Dominica
              last edited by

              So could you break into the PBX from the phone using this backdoor?

              scottalanmillerS 1 Reply Last reply Reply Quote 0
              • scottalanmillerS
                scottalanmiller @Dominica
                last edited by

                @Dominica said:

                So could you break into the PBX from the phone using this backdoor?

                Not per se. But you would get access to the extension's credentials so you could do some damage. But only through the extension.

                1 Reply Last reply Reply Quote 0
                • DominicaD
                  Dominica
                  last edited by

                  Ah, okay. So you could do things like hijack the extension and make a bunch of calls, but not break in and take over the whole system?

                  scottalanmillerS 1 Reply Last reply Reply Quote 0
                  • scottalanmillerS
                    scottalanmiller @Dominica
                    last edited by

                    @Dominica exactly. And you would be struggling to even do that. If locked down the extension would be locked by IP range and the phone would hopefully be blocked from making its own external VPN connections. So it really would only be a gateway to other security flaws. On its own it should do very little.

                    1 Reply Last reply Reply Quote 1
                    • 1 / 1
                    • First post
                      Last post