Yeastar ออก Security Advisory ระดับ Critical หลังพบว่าแฮกเกอร์ใช้เทคนิคขั้นสูงเจาะระบบ PBX ที่เปิด Public IP
Yeastar P-Series PBX V23.3 มีการอัปเดตความปลอดภัยด่วน เนื่องจากพบการโจมตีจากแฮกเกอร์ผ่าน Public IP องค์กรที่ใช้งานระบบนี้ควรอัปเกรดทันทีเพื่อป้องกันความเสียหาย
👉 หากคุณใช้ P-Series PBX และยังไม่อัปเดต คุณกำลังเสี่ยงโดนแฮ็กโดยไม่รู้ตัว Yeastar P-Series PBX V23.3
⚠️ ความเสี่ยง (Critical Risk) Yeastar P-Series PBX V23.3
💣 รูปแบบการโจมตีล่าสุด Yeastar P-Series PBX V23.3

✔ แฮกเกอร์ใช้ Bot สแกน Public IP
✔ เจาะเข้า PBX Management Portal
✔ bypass ระบบป้องกันแบบ IP-based
💸 ผลกระทบที่เกิดขึ้น Yeastar P-Series PBX V23.3
-
โทรออกต่างประเทศโดยไม่ได้รับอนุญาต (Toll Fraud)
-
ค่าโทรพุ่งหลักแสน/ล้าน
-
ระบบล่ม / ใช้งานไม่ได้
-
ข้อมูลรั่ว
👉 ระดับความเสี่ยง: CRITICAL / วิกฤต
🎯 ระบบที่มีความเสี่ยงสูง Yeastar P-Series PBX V23.3
📌 ผลิตภัณฑ์ที่ได้รับผลกระทบ
-
P-Series Software Edition (PSE)
-
P-Series Appliance Edition (PAE)
-
P-Series Cloud Edition (PCE)
❌ S-Series PBX = ไม่ได้รับผลกระทบ
⚠️ ระบบที่เสี่ยงหนักมาก Yeastar P-Series PBX V23.3
-
ใช้ Public IP ตรง (Direct Exposure)
-
ไม่มี Firewall หรือ Rule ไม่เข้มงวด
-
ใช้ Extension เป็น Username login
👉 = โดนยิงได้ง่ายมาก
🚀 วิธีแก้ (ต้องทำทันที)
✅ อัปเกรดเป็น V23.3 GA ด่วน

👉 เวอร์ชัน: V23.3 GA (XX.22.0.139)
✔ เพิ่ม Security Layer ใหม่
✔ ป้องกันการโจมตีรูปแบบล่าสุด
🔧 วิธีอัปเกรด
📍 แบบเครื่องเดียว
-
เข้า: Maintenance > Upgrade
-
เลือกเวอร์ชัน → Upgrade Now
📍 แบบหลายเครื่อง
-
ใช้ Yeastar Central Management (YCM)
-
หรือ Remote Management Premium (RMP)
👉 เหมาะกับองค์กร / SI / Multi-site
🔐 Best Practice (ต้องทำเพิ่ม)
🛡️ ปิดช่องโหว่ทันที

✔ ห้ามเปิด Public IP ตรง
✔ ปิด Port Forward
✔ ใช้ VPN / Remote Access
🔑 เพิ่มความปลอดภัย
-
ใช้รหัสผ่านแข็งแรง
-
ไม่ใช้ Extension เป็น Username
-
เปิด 2FA
📞 ควบคุมการโทร
-
จำกัดปลายทางโทรออก
-
ตั้ง Call Permission
👉 กัน “Toll Fraud” ได้จริง
#Yeastar #PBXSecurity #VoIPSecurity #CyberSecurity #PBXPublicIP #VoIPHacking #TollFraud #SecurePBX #FirewallPBX #IPPhoneSystem #UnifiedCommunication #UCSystem #NetworkSecurity #PBXThailand #VoIPThailand #ระบบโทรศัพท์องค์กร #ความปลอดภัยPBX #SystemIntegrator #CloudPBX #ITSecurity
Why This Yeastar P-Series PBX V23.3 Update Matters
This update matters because attackers actively scan for exposed PBX systems. First, they look for systems reachable via public IP without proper firewall rules. Then, they attempt to exploit known vulnerabilities. As a result, unpatched systems can suffer toll fraud or data breaches within hours.
How to Upgrade Safely
Upgrading requires a few steps. First, back up the current configuration. Then, download the official firmware from Yeastar. However, always test the upgrade on a non-production system first if possible. Afterward, schedule a maintenance window to minimize disruption.
สำหรับข้อมูลด้านความปลอดภัยเพิ่มเติมเกี่ยวกับ Yeastar P-Series PBX V23.3 และระบบ IP PBX สำหรับองค์กร ติดต่อทีม UC Gangster ได้ที่ หน้าแรกของ UC Gangster หรือดูประกาศอย่างเป็นทางการที่ Yeastar Support Center.
What Happens If You Don’t Upgrade
Delaying the upgrade carries real risk. For example, attackers who gain access can make unauthorized international calls, generating massive phone bills within days. Additionally, they may intercept call recordings or voicemail data. Therefore, IT teams should treat this update as a priority, not an optional task.
Additional Hardening Steps
Beyond the firmware update, additional hardening helps. First, restrict web management access to trusted IP ranges only. Then, disable any unused services on the PBX. Similarly, enforce strong passwords for all extensions. As a result, the system becomes much harder to compromise even if a vulnerability is later discovered.
Getting Help With the Upgrade
Getting professional help speeds things up. For instance, a certified integrator can validate the firmware version safely. Meanwhile, they can also review your firewall rules for additional gaps. In fact, most organizations complete the entire process within a single afternoon when working with an experienced partner.
สนใจอัปเกรดหรือเปลี่ยนเป็น Yeastar P-Series
ดูรายละเอียด Yeastar P-Series IP PBX ราคา รุ่นล่าสุดที่ปิดช่องโหว่ความปลอดภัยแล้ว สอบถามเพิ่มเติมได้ที่ UC Gangster โทร 02-026-6220 หรือ LINE @ucgangster

