{"id":8004,"date":"2020-02-10T08:26:40","date_gmt":"2020-02-10T08:26:40","guid":{"rendered":"https:\/\/www.securitytoday.de\/2026\/04\/02\/post_id-1928\/"},"modified":"2026-07-04T12:26:37","modified_gmt":"2026-07-04T12:26:37","slug":"nfon-patches-security-vulnerability-in-yealink-phones","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2020\/02\/10\/nfon-patches-security-vulnerability-in-yealink-phones\/","title":{"rendered":"NFON Patches Security Vulnerability in Yealink Phones"},"content":{"rendered":"<p><strong>Security vulnerabilities in the auto-provisioning feature of certain Yealink IP phones were already identified in November 2019. According to c\u2019t magazine, the major Chinese manufacturer failed to respond adequately for two months  &#8211;  but NFON did act.<\/strong><\/p>\n<h2>TL;DR<\/h2>\n<ul>\n<li>Cybersecurity is a board-level responsibility, not just an IT issue<\/li>\n<li>The threat landscape continues to intensify  &#8211;  proactive action is essential<\/li>\n<li>Investments in prevention are significantly cheaper than damage control<\/li>\n<li>Regulatory requirements for IT security are rising across Europe<\/li>\n<\/ul>\n<p>Auto-provisioning is generally a convenient feature, enabling simple and centralized configuration of IP phones. However, security flaws in certain devices from Yealink show it\u2019s not without risks. Yealink  &#8211;  whose Chinese name Yi Lian means \u201cto connect hundreds of millions\u201d  &#8211;  is no minor player, but rather one of the market leaders. In fact, Frost &#038; Sullivan named Yealink the global number one provider of SIP phones in 2018.<\/p>\n<p>Despite this, according to a recent <a href=\"https:\/\/www.heise.de\/ct\/artikel\/VoIP-Telefone-Schwere-Sicherheitsluecke-bei-Yealink-entdeckt-4654580.html\">report in Heise\u2019s c\u2019t magazine<\/a> from February 7, 2020, Yealink failed to respond adequately for over two months to inquiries regarding a security vulnerability discovered by the IT security firm VTRUST in the auto-provisioning process of certain IP phones.<\/p>\n<p>Moreover, the Chinese manufacturer only provided contact details upon request via its Facebook account, as noted in the c\u2019t report. Incidentally, this once again highlights the growing trend of users turning to social media channels, where vendors tend to respond faster than to phone calls or emails.<\/p>\n<p>Yealink promised to address the issue urgently and requested technical details from VTRUST. The IT security provider then notified more than 20 German VoIP providers via email, fax, and registered mail about the potential security risks. Nevertheless, according to the Heise article, even two months after the initial contact, Yealink had still not managed to close the security gap.<\/p>\n<p>While end users could do little in response, VoIP providers had more options. One of the providers notified by VTRUST had already resolved the issue using two-factor authentication (2FA), c\u2019t reports. The article does not reveal which provider it was.<\/p>\n<p>In fact, it was NFON AG. The company offers Yealink IP phones among others and had already effectively fixed the security vulnerability described by Heise using the aforementioned two-factor authentication on January 30. NFON has also filed a patent for the solution, in line with its guiding principle of \u201cSafety first.\u201d Specifically, during the setup of new phones, in addition to any hardware-bound certificates, users must now enter a one-time Phone Authentication PIN (PAP). The six-digit PAP code functions similarly to online banking security procedures, according to NFON, significantly enhancing protection.<\/p>\n<p><strong>Fact:<\/strong> German companies invest an average of 14 percent of their IT budget in cybersecurity, according to Bitkom.<\/p>\n<p><strong>Fact:<\/strong> According to AV-TEST, over 450,000 new malware variants are discovered daily.<\/p>\n<h2>Key Facts<\/h2>\n<p><strong>Damage Volume:<\/strong> Cybercrime causes global annual damages exceeding 8 trillion Euro.<\/p>\n<p><strong>Skills Shortage:<\/strong> More than 3.5 million cybersecurity professionals are missing worldwide.<\/p>\n<h2>Frequently Asked Questions<\/h2>\n<p class=\"st-faq-hint\">Every question is locked. A tap unlocks the answer.<\/p>\n<details>\n<summary><strong>What are the most common cyber threats for businesses?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">According to the BSI threat report, ransomware, phishing, DDoS attacks, and supply chain compromises are the most prevalent threats. German businesses also face regulatory risks (GDPR, NIS2).<\/p>\n<\/details>\n<details>\n<summary><strong>How much should a company invest in cybersecurity?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Industry experts recommend allocating 10 to 15 percent of the IT budget to cybersecurity. German companies, according to Bitkom, average 14 percent. What matters is not only the amount but also the strategic allocation across prevention, detection, and response.<\/p>\n<\/details>\n<details>\n<summary><strong>Does every company need a CISO?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Not every company needs a full-time CISO, but every company needs clear accountability for IT security at the executive level. SMEs can rely on an external CISO (Virtual CISO). Under NIS2, management responsibility is now legally mandated.<\/p>\n<\/details>\n<h2>Related Articles<\/h2>\n<ul>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/05\/post_id-3821\/\">secIT by Heise 2026: The Security Roadshow for Admins and IT Managers<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/05\/post_id-3819\/\">DsiN Annual Congress 2026: Digital Security in a Connected Society<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/05\/cybersec-europe-2026-brussels-security-conference-at-the-heart-of-eu-regulation\/\">Cybersec Europe 2026: Brussels\u2019 Security Conference at the Heart of EU Regulation<\/a><\/li>\n<\/ul>\n<p style=\"font-weight:700;color:#e6e3da;font-size:1.05em;margin:48px 0 16px;\">More from the MBF Media Network<\/p>\n<div style=\"display:flex;flex-direction:column;gap:14px;margin-bottom:40px;\"><a href=\"https:\/\/www.digital-chiefs.de\" class=\"st-net-card\" style=\"display:block;padding:16px 18px;background:#23261f;border:1px solid rgba(105,216,237,0.22);border-radius:10px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 2px 10px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;\"><span style=\"display:block;margin-bottom:6px;font-size:0.72em;font-weight:700;letter-spacing:0.06em;text-transform:uppercase;color:#d65663;\">Digital Chiefs<\/span><span style=\"display:block;color:#e6e3da;line-height:1.45;\">Strategic IT Decisions for Executives<\/span><\/a><a href=\"https:\/\/www.mybusinessfuture.com\" class=\"st-net-card\" style=\"display:block;padding:16px 18px;background:#23261f;border:1px solid rgba(105,216,237,0.22);border-radius:10px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 2px 10px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;\"><span style=\"display:block;margin-bottom:6px;font-size:0.72em;font-weight:700;letter-spacing:0.06em;text-transform:uppercase;color:#aa8ac2;\">MyBusinessFuture<\/span><span style=\"display:block;color:#e6e3da;line-height:1.45;\">Business Future: Trends for Decision Makers<\/span><\/a><\/div>\n","protected":false},"excerpt":{"rendered":"Security vulnerabilities in the auto-provisioning feature of certain Yealink IP phones were already identified in November 2019. According to c\u2019t magazine, the major Chinese manufacturer failed to respond adequately for two months &#8211; but NFON did act. TL;DR Cybersecurity is a board-level responsibility, not just an IT issue The threat landscape continues to intensify &#8211; [&hellip;]","protected":false},"author":55,"featured_media":1930,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"yealink phones","_yoast_wpseo_title":"NFON Patches Security Vulnerability in Yealink Phones","_yoast_wpseo_metadesc":"NFON patches security vulnerability in Yealink phones\u2014protect your data now. Learn how to stay safe and secure your communication today.","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"","_yoast_wpseo_twitter-image-id":0,"_evm_slot_owner":"","evm_cvss":0,"evm_risk":0,"evm_casefile":"","evm_primary_cve":"","evm_pin_until":0,"evm_external_preview_token":"","evm_external_preview_expires":"","_evm_translation_lang":"","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":["post_id-1928"],"footnotes":""},"categories":[215,255],"tags":[],"class_list":["post-8004","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-case-studies","category-praxis-umsetzung-en"],"evm_reading_time_minutes":4,"wpml_language":"en","wpml_translation_of":1928,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/8004","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/55"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=8004"}],"version-history":[{"count":7,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/8004\/revisions"}],"predecessor-version":[{"id":19896,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/8004\/revisions\/19896"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/1930"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=8004"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=8004"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=8004"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}