Description
Yealink SIP-T33G firmware versions 124.86.x.x prior to 124.87.0.0 contain a race condition vulnerability that allows authenticated attackers to interrupt active diagnostic processes by concurrently deleting output files written to predictable paths under the diagnostic directory. Attackers can trigger a diagnostic operation such as traceroute or ping and simultaneously invoke the file deletion endpoint to terminate the running process, leaving the system in an inconsistent state.
Published: 2026-09-14
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (diagnostic failure)
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a race condition (CWE-362) that allows an authenticated user to terminate running diagnostic processes by deleting output files written to predictable paths, causing diagnostic failures and leaving the device in an inconsistent state.

Affected Systems

Affected devices include Yealink SIP‑T33G IP phones running firmware versions 124.86.x.x or earlier than 124.87.0.0, which contain the race condition.

Risk and Exploitability

The CVSS base score is 6, indicating moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires authenticated access to the phone and the ability to trigger diagnostic commands while simultaneously invoking the file‑deletion endpoint. Because the attack needs an active session, the risk is limited to compromised devices or trusted users, but the lack of higher severity may reduce urgency; nevertheless, patching is recommended to eliminate the race condition.

Generated by OpenCVE AI on September 15, 2026 at 13:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the device firmware to version 124.87.0.0 or later to remove the race condition.
  • Disable or restrict access to the diagnostic file‑deletion endpoint to prevent concurrent deletion during diagnostics.
  • If a firmware update cannot be applied immediately, configure the device to deny or limit concurrent file‑deletion requests from authenticated users while diagnostic operations are in progress.

Generated by OpenCVE AI on September 15, 2026 at 13:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description Yealink SIP-T33G firmware versions 124.86.x.x prior to 124.87.0.0 contain a race condition vulnerability that allows authenticated attackers to interrupt active diagnostic processes by concurrently deleting output files written to predictable paths under the diagnostic directory. Attackers can trigger a diagnostic operation such as traceroute or ping and simultaneously invoke the file deletion endpoint to terminate the running process, leaving the system in an inconsistent state.
Title Yealink SIP-T33G < 124.87.0.0 Race Condition via Diagnostic File Deletion
Weaknesses CWE-362
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-14T18:12:06.587Z

Reserved: 2026-04-27T14:20:27.676Z

Link: CVE-2026-7208

cve-icon Vulnrichment

Updated: 2026-09-14T16:14:32.634Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T14:17:12.120

Modified: 2026-09-24T20:28:01.780

Link: CVE-2026-7208

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T14:00:11Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')