CVE-2026-7208

Yealink SIP-T33G firmware versions 124.86.x.x prior to 124.87.0.0 contain a race condition vulnerability that allows authenticated attackers to interrupt active diagnostic processes by concurrently deleting output files written to predictable paths under the diagnostic directory. Attackers can trigger a diagnostic operation such as traceroute or ping and simultaneously invoke the file deletion endpoint to terminate the running process, leaving the system in an inconsistent state.

Scoring

Severity
MEDIUM
CVSS base score
6
CVSS vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
EPSS probability
0.23%
CWE
CWE-362
Published
2026-09-14
Last modified
2026-09-14

Affected products

Weakness type

Markdown version · Browse all CVEs