CVE Vulnerabilities

CVE-2022-48625

Use of Hard-coded Cryptographic Key

Published: Feb 20, 2024 | Modified: Aug 26, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Yealink Config Encrypt Tool add RSA before 1.2 has a built-in RSA key pair, and thus there is a risk of decryption by an adversary.

Weakness

The product uses a hard-coded, unchangeable cryptographic key.

Affected Software

NameVendorStart VersionEnd Version
Configuration_encryption_toolYealink*1.2 (excluding)

Potential Mitigations

References