Impact
The vulnerability is a race condition (CWE-362) that allows an authenticated user to terminate running diagnostic processes by deleting output files written to predictable paths, causing diagnostic failures and leaving the device in an inconsistent state.
Affected Systems
Affected devices include Yealink SIP‑T33G IP phones running firmware versions 124.86.x.x or earlier than 124.87.0.0, which contain the race condition.
Risk and Exploitability
The CVSS base score is 6, indicating moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires authenticated access to the phone and the ability to trigger diagnostic commands while simultaneously invoking the file‑deletion endpoint. Because the attack needs an active session, the risk is limited to compromised devices or trusted users, but the lack of higher severity may reduce urgency; nevertheless, patching is recommended to eliminate the race condition.
OpenCVE Enrichment