CVE Vulnerabilities

CVE-2022-48625

Use of Hard-coded Cryptographic Key

Published: Feb 20, 2024 | Modified: Apr 02, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Yealink Config Encrypt Tool add RSA before 1.2 has a built-in RSA key pair, and thus there is a risk of decryption by an adversary.

Weakness

The use of a hard-coded cryptographic key significantly increases the possibility that encrypted data may be recovered.

Affected Software

Name Vendor Start Version End Version
Config_encrypt_tool_add_rsa Yealink * 1.2 (excluding)

Potential Mitigations

References