CloudAware Security Advisory CVE-2024-24681: Insecure AES key in Yealink Configuration Encrypt Tool ======================================================================== Summary ======================================================================== A single, vendorwide, hardcoded AES key in the configuration tool used to encrypt provisioning documents was leaked leading to a compromise of confidentiality of provisioning documents. ======================================================================== Product ======================================================================== * Yealink Configuration Encrypt Tool (AES version) * Yealink Configuration Encrypt Tool (RSA version