Critical Update: Protect Your PBX Against Phone Fraud

Cybercriminals have refined their methods for targeting IP PBX systems, creating a major risk of phone fraud. Yeastar urges you to upgrade to P‑Series V23.3 GA to secure your infrastructure and avoid significant financial losses.

Risk Summary

Attackers use automated tools to scan public IP addresses and specific ports to locate PBXs. Once they gain access to the management portal, they can place unauthorized outgoing calls, resulting in fraudulent charges and disruption of communication services.

Affected Systems

Exposed P‑Series products (Software, Appliance, and Cloud), including installations on public cloud with direct IP access, configurations without a strict firewall, and portals using extension numbers as credentials. S‑Series PBXs are not affected.

Mandatory Update to V23.3 GA

To protect your PBX, download version XX.22.0.139 (V23.3 GA) and apply it through the management portal (Maintenance > Upgrade) or using the downloaded firmware. Cloud deployments use YCM to schedule batch updates, while PAE/PSE versions can be updated in batches through Yeastar Remote Management Premium.

Additional Security Practices

In addition to updating, secure your network by avoiding port forwarding, blocking unauthorized IPs, strengthening authentication with strong passwords and granular access controls, and restricting outgoing calls to prevent fraud.

Technical Support

If you encounter an issue during the update or need assistance, contact the Yeastar technical support team. Support images are available to guide you.

The Yeastar team supports businesses and integrators in assessing their needs, selecting an architecture, and preparing for deployment.