ZeroHour

CVE-2018-17563

CVSS 3.0
5.3 medium
EPSS
<1%p51
Published
()
Modified
Description

A Malformed Input String to /cgi-bin/api-get_line_status on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to dump the device's configuration in cleartext.

Vendors
grandstream
Products
gxp1610 firmware, gxp1615 firmware, gxp1620 firmware, gxp1625 firmware, gxp1628 firmware, gxp1630 firmware
Weakness
CWE-311
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.