Yealink Device Management contains a server-side request forgery (SSRF) vulnerability that allows for unauthenticated remote code execution.
Source: NVD ↗ · CISA KEV Catalog ↗