CVE-2026-2329
largeUnauthenticated RCE via stack buffer overflow in Grandstream GXP1600-series VoIP phones
An unauthenticated stack-based buffer overflow (CWE-121) exists in the HTTP API endpoint /cgi-bin/api.values.get on Grandstream GXP1600-series VoIP desk phones. A remote attacker who can reach the phone's web API can send a crafted request to this endpoint with no credentials, overflowing a stack buffer and executing code with root privileges on the device. Full root control gives attackers a stealthy network foothold inside the victim network, with the potential to intercept calls or pivot to other systems. All six models in the series are affected: GXP1610, GXP1615, GXP1620, GXP1625, GXP1628, and GXP1630. No public proof-of-concept or confirmed in-the-wild exploitation is known yet, but EPSS assigns a 40% probability of exploitation within 30 days (99th percentile), so rapid weaponization is likely.
What to do: Upgrade all GXP1600-series phones (GXP1610/1615/1620/1625/1628/1630) to the latest firmware available from Grandstream, per the vendor advisory. Until patched, do not expose the phones' HTTP management interface to the internet, restrict access to it from untrusted networks, and review web server logs for requests to /cgi-bin/api.values.get as a sign of probing or compromise. Also check affected devices for indicators of exploitation such as unexpected call behavior, call interception, or unusual outbound traffic.
| Grandstream GXP1610 firmware | All firmware versions (no specific version ranges or fixed version provided in the data) |
| Grandstream GXP1615 firmware | All firmware versions (no specific version ranges or fixed version provided in the data) |
| Grandstream GXP1620 firmware | All firmware versions (no specific version ranges or fixed version provided in the data) |
| Grandstream GXP1625 firmware | All firmware versions (no specific version ranges or fixed version provided in the data) |
| Grandstream GXP1628 firmware | All firmware versions (no specific version ranges or fixed version provided in the data) |
| Grandstream GXP1630 firmware | All firmware versions (no specific version ranges or fixed version provided in the data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An unauthenticated stack-based buffer overflow vulnerability exists in the HTTP API endpoint /cgi-bin/api.values.get. A remote attacker can leverage this vulnerability to achieve unauthenticated remote code execution (RCE) with root privileges on a target device. The vulnerability affects all six device models in the series: GXP1610, GXP1615, GXP1620, GXP1625, GXP1628, and GXP1630.
- Vendors
- grandstream
- Products
- gxp1610 firmware, gxp1615 firmware, gxp1620 firmware, gxp1625 firmware, gxp1628 firmware, gxp1630 firmware
- Weakness
- CWE-121
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X