NFON Patches Security Vulnerability in Yealink Phones
Security vulnerabilities in the auto-provisioning feature of certain Yealink IP phones were already identified in November 2019. According to c’t magazine, the major Chinese manufacturer failed to respond adequately for two months – but NFON did act.
TL;DR
- Cybersecurity is a board-level responsibility, not just an IT issue
- The threat landscape continues to intensify – proactive action is essential
- Investments in prevention are significantly cheaper than damage control
- Regulatory requirements for IT security are rising across Europe
Auto-provisioning is generally a convenient feature, enabling simple and centralized configuration of IP phones. However, security flaws in certain devices from Yealink show it’s not without risks. Yealink – whose Chinese name Yi Lian means “to connect hundreds of millions” – is no minor player, but rather one of the market leaders. In fact, Frost & Sullivan named Yealink the global number one provider of SIP phones in 2018.
Despite this, according to a recent report in Heise’s c’t magazine from February 7, 2020, Yealink failed to respond adequately for over two months to inquiries regarding a security vulnerability discovered by the IT security firm VTRUST in the auto-provisioning process of certain IP phones.
Moreover, the Chinese manufacturer only provided contact details upon request via its Facebook account, as noted in the c’t report. Incidentally, this once again highlights the growing trend of users turning to social media channels, where vendors tend to respond faster than to phone calls or emails.
Yealink promised to address the issue urgently and requested technical details from VTRUST. The IT security provider then notified more than 20 German VoIP providers via email, fax, and registered mail about the potential security risks. Nevertheless, according to the Heise article, even two months after the initial contact, Yealink had still not managed to close the security gap.
While end users could do little in response, VoIP providers had more options. One of the providers notified by VTRUST had already resolved the issue using two-factor authentication (2FA), c’t reports. The article does not reveal which provider it was.
In fact, it was NFON AG. The company offers Yealink IP phones among others and had already effectively fixed the security vulnerability described by Heise using the aforementioned two-factor authentication on January 30. NFON has also filed a patent for the solution, in line with its guiding principle of “Safety first.” Specifically, during the setup of new phones, in addition to any hardware-bound certificates, users must now enter a one-time Phone Authentication PIN (PAP). The six-digit PAP code functions similarly to online banking security procedures, according to NFON, significantly enhancing protection.
Fact: German companies invest an average of 14 percent of their IT budget in cybersecurity, according to Bitkom.
Fact: According to AV-TEST, over 450,000 new malware variants are discovered daily.
Key Facts
Damage Volume: Cybercrime causes global annual damages exceeding 8 trillion Euro.
Skills Shortage: More than 3.5 million cybersecurity professionals are missing worldwide.
Frequently Asked Questions
Every question is locked. A tap unlocks the answer.
What are the most common cyber threats for businesses?
According to the BSI threat report, ransomware, phishing, DDoS attacks, and supply chain compromises are the most prevalent threats. German businesses also face regulatory risks (GDPR, NIS2).
How much should a company invest in cybersecurity?
Industry experts recommend allocating 10 to 15 percent of the IT budget to cybersecurity. German companies, according to Bitkom, average 14 percent. What matters is not only the amount but also the strategic allocation across prevention, detection, and response.
Does every company need a CISO?
Not every company needs a full-time CISO, but every company needs clear accountability for IT security at the executive level. SMEs can rely on an external CISO (Virtual CISO). Under NIS2, management responsibility is now legally mandated.
Related Articles
- secIT by Heise 2026: The Security Roadshow for Admins and IT Managers
- DsiN Annual Congress 2026: Digital Security in a Connected Society
- Cybersec Europe 2026: Brussels’ Security Conference at the Heart of EU Regulation
More from the MBF Media Network