CVE-2024–31747 || Yealink VP59 Microsoft Teams Phone Lock Bypass

Deepak
4 min readApr 2, 2024
2022041403345046ca91bd56409d853c8a7745804ad2.png

Note: Throughout the video proof of concept (POC) creation phase, there was no disclosure or exposure of any employee, organizational, or user data, ensuring strict adherence to data privacy protocols and maintaining the confidentiality of sensitive information.

During a private assessment, a security vulnerability was discovered. This vulnerability allows to bypass phone lock of the device.

Affected Product : Yealink VP59 Microsoft Teams Phone

Affected Firmware Version: 91.15.0.118

Fixed Firmware Version: 122.15.0.142

Steps to Reproduce:

  1. Activate the device to initiate its functions and operations seamlessly, ensuring a smooth start-up process.
  2. Access the device by logging in with your Microsoft Teams account credentials, providing authorized entry for personalized usage.

3. Configure device security settings by implementing a 30-second phone lock, optimizing convenience for testing purposes

--

--