Yealink RPS and Security Updates (August - October 2025)
VoIP Phones

Yealink RPS and Security Updates (August - October 2025)

Yealink have recently released some improvements to their legacy auto provisioning system, including important changes that may impact your ability to use their handsets with your VoIP provider.

 

1. Stricter IP and MAC Address Security Measures

 

Yealink is implementing stricter security measures that may block certain handsets from connecting to their RPS (Redirection and Provisioning Service).

 

What This Means for You

  • - Blocked connections: Handsets may be blocked if connecting from a new IP address or if they are older, End-of-Life (EOL) models (manufactured before 2020).
  • - Provisioning failures: If blocked, the handset's IP and MAC Address will be unable to re-provision. For example, a factory-reset device will remain blank and won't be able to receive a new configuration.

 

Our Solution

  • - Firmware update: Yealink have released new firmware for some EOL models (see section below). Handsets will need to be updated where possible.
  • - Manual Serial Number entry: If an updated device without a Serial Number sends a request to the Yealink RPS, the handset will prompt for the last 5 digits of the Serial Number (printed on a label on the bottom of the handset) to be entered via the keypad. Once entered, provisioning will be allowed to proceed.
  • - Manual whitelisting: In some exceptional situations, Yealink may block the IP address of the requesting handset. This will prevent all handsets using that IP address from provisioning. Currently, we cannot whitelist these devices ourselves, but our Support team will be whitelisting IPs and devices upon request. Please submit a support ticket if you encounter this issue, by emailing help@yay.com.

 

2. Secure PIN Requirement

 

Yealink's latest RPS server now requires a PIN for initial provisioning on some handsets. This PIN must be retrieved from their provisioning portal by us, and passed to you to be entered manually into the device.

 

What This Means for You

  • - PIN required: Handsets on older firmware versions will need a PIN to provision.
  • - Firmware update: Upgrading to the latest firmware will enable the PIN functionality. Newer handsets will authenticate automatically, but EOL (End-of-Life) models will need a firmware update to support the PIN feature.

 

Our Solution

  • - For users: PINs are now displayed in the Hardware section of customer dashboards. You can also download the CSV of all of the accounts hardware, in it, column L will also display any RPS PINs, so you don't have to pull it one by one.

 

For more information, please see the official Yealink support article:

 https://support.yealink.com/en/portal/knowledge/show?id=687065ed62c0b13e52f16ab6

 

3. EOL of the Old RPS Server (from 1st Oct 2025)

 

Starting 1st October 2025, Yealink is decommissioning its legacy RPS platform. This change will impact some End-of-Life Yealink handset models as well as current devices running older firmware versions.

 

What This Means for You

  • - Auto-provisioning will fail: Handsets on older firmware will no longer be able to auto-provision using Yealink's zero-touch service.
  • - Manual configuration needed: If a handset is factory reset after 1st October 2025, it will need to be manually configured with a supported firmware in order to connect to the new RPS server.
  • - Our role: While we always recommend using a supported/in-life model, our in-house auto-provisioning server can still be used for all handset models. You can manually enter the provisioning URL http://firstprovision.voipcp.com/yealink/ to provision handsets.

 

Our Recommended Solution

  • - For users: To prevent any issues, we will be updating the firmware on all connected Yealink devices with "Get Latest Firmware" enabled before 1st October 2025. If this option is not enabled, the device will need to be updated manually.

 

For more information, please see the official Yealink support article: https://support.yealink.com/en/portal/knowledge/show?id=687f7b3706b3cf2066d84dea

 

Yealink have provided new firmware for some EOL models as a temporary measure (see table below), however, we cannot guarantee how long this will be supported:

 

Model

Unsupported Version


Will connect to new RPS server, ask for PIN every time

Recommended Version


Will connect to RPS for one time

Yealink Temporary Firmware
SIP-T56A/ 58ALower than 58.84.0.3758.86.0.165N/A
SIP-CP920Lower than 78.84.0.12178.86.0.165N/A
CP960Lower than 73.84.0.3773.86.0.165N/A
W52PLower than 25.81.0.6725.81.0.165
Handset
W52H: 26.81.0.165
W56H: 61.81.0.165
N/A
W60BLower than 77.83.0.8377.85.0.165
Handset
W53HV85: 88.85.0.91
W56HV85: 61.85.0.93
W59RV85: 115.85.0.89
N/A
SIP-T19P_E2Lower than 53.84.0.12153.84.0.165If firmware version is V83 or lower, please also upgrade to the designated firmware

If firmware version is higher than V83, please upgrade to the latest version x.x.0.165 directly.
SIP-T21P_E2Lower than 52.84.0.12152.84.0.165If firmware version is V83 or lower, please also upgrade to the designated firmware

If firmware version is higher than V83, please upgrade to the latest version x.x.0.165 directly.
SIP-T23GLower than 44.84.0.12144.84.0.165If firmware version is V83 or lower, please also upgrade to the designated firmware

If firmware version is higher than V83, please upgrade to the latest version x.x.0.165 directly.
SIP-T40GLower than 76.84.0.12176.84.0.165If firmware version is V83 or lower, please also upgrade to the designated firmware

If firmware version is higher than V83, please upgrade to the latest version x.x.0.165 directly.
SIP-T40PLower than 54.84.0.12154.84.0.165If firmware version is V83 or lower, please also upgrade to the designated firmware

If firmware version is higher than V83, please upgrade to the latest version x.x.0.165 directly.
SIP-T27GLower than 69.84.0.12169.86.0.165If firmware version is V83 or lower, please also upgrade to the designated firmware

If firmware version is higher than V83, please upgrade to the latest version x.x.0.165 directly.
SIP-T41S/42S/46S/48SLower than 66.84.0.12166.86.0.165If firmware version is V83 or lower, please also upgrade to the designated firmware

If firmware version is higher than V83, please upgrade to the latest version x.x.0.165 directly.
SIP-T29G46.83.0.160 and below46.83.0.165If firmware version is V82 or lower, please upgrade to the designated firmware to address the RPS-related issue.
SIP-T27P45.83.0.160 and belowNo new version available for RPS service accessIf firmware version is V82 or lower, please upgrade to the designated firmware to address the RPS-related issue.
SIP-T41P36.83.0.160 and belowNo new version available for RPS service accessIf firmware version is V82 or lower, please upgrade to the designated firmware to address the RPS-related issue.
SIP-T42G29.83.0.160 and belowNo new version available for RPS service accessIf firmware version is V82 or lower, please upgrade to the designated firmware to address the RPS-related issue.
SIP-T46G28.83.0.160 and belowNo new version available for RPS service accessIf firmware version is V82 or lower, please upgrade to the designated firmware to address the RPS-related issue.
SIP-T48G35.83.0.160 and belowNo new version available for RPS service accessIf firmware version is V82 or lower, please upgrade to the designated firmware to address the RPS-related issue.
Other EOL Models:
SIP-T19P
SIP-T20P/22P/26P/28P
SIP-T32G/38G
T52S/54S
CP860
All versions no longer support RPS service accessNo new version available for RPS service access 

 

Other provisioning methods that do not use Yealink's RPS

 

Option 66 - Non-RPS Provisioning Method

 

If a device cannot connect to Yealink RPS, it can still be auto-provisioned for use.

 

This approach is ideal for larger installations where manually updating each handset would be time consuming, but does require some technical knowledge as access to the router and/or firewall is needed.

  1. 1. Update the local sites DHCP server which provides IP addresses to the handsets.
  2. 2. In the DHCP settings, Option 66 (TFTP Server) needs to be set to: http://firstprovision.voipcp.com/yealink/
  3. 3. Handsets requesting IP addresses will also be served this URL and will use it in preference to the default Yealink server.

This will bypass the Yealink RPS and direct the handsets to the provisioning server directly where they can auto-provision successfully.

 

We are unable to provide specific instructions for the many different brands of routers available. If unable to use the above method, then please refer to the per-handset GUI method below.

 

Manual Handset Configuration (via GUI)

  1. 1. Log in to the handset on the local network
  2. 2. Go to Settings > Auto Provision
  3. 3. In "Server URL" add http://firstprovision.voipcp.com/yealink/
  4. 4. Select "Auto Provision now"

 

This will bypass the Yealink RPS and direct the handset to the server directly where it can auto provision successfully.

 

Please note - If the handset is factory reset then this will need to be set again before it can point to our provisioning server.

If you need any further help, please don't hesitate to contact our friendly Support team.

Did you find this helpful?

New to Cloud Telephony?
Join one of our free live webinars!
Join one of our twice weekly webinars for a guided tour of our business phone system and features.