Yealink RPS before 2025-06-27 allows unauthorized access to information, including AutoP URL addresses. This was fixed by deploying an enhanced authentication mechanism through a security update to all cloud instances.
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.