ZeroHour

Vulnerabilities

44 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-2329
Unauthenticated RCE via stack buffer overflow in Grandstream GXP1600-series VoIP phones

An unauthenticated stack-based buffer overflow (CWE-121) exists in the HTTP API endpoint /cgi-bin/api.values.get on Grandstream GXP1600-series VoIP desk phones. A remote attacker who can reach the phone's web API can send a crafted request to this endpoint with no credentials, overflowing a stack buffer and executing code with root privileges on the device. Full root control gives attackers a stealthy network foothold inside the victim network, with the potential to intercept calls or pivot to other systems. All six models in the series are affected: GXP1610, GXP1615, GXP1620, GXP1625, GXP1628, and GXP1630. No public proof-of-concept or confirmed in-the-wild exploitation is known yet, but EPSS assigns a 40% probability of exploitation within 30 days (99th percentile), so rapid weaponization is likely.

Do: Upgrade all GXP1600-series phones (GXP1610/1615/1620/1625/1628/1630) to the latest firmware available from Grandstream, per the vendor advisory. Until patched, do not expose the phones' HTTP management interface to the internet, restrict access to it from untrusted networks, and review web server logs for requests to /cgi-bin/api.values.get as a sign of probing or compromise. Also check affected devices for indicators of exploitation such as unexpected call behavior, call interception, or unusual outbound traffic.

9.340%
  • Grandstream GXP1610 firmware All firmware versions (no specific version ranges or fixed version provided in the data)
  • Grandstream GXP1615 firmware All firmware versions (no specific version ranges or fixed version provided in the data)
  • Grandstream GXP1620 firmware All firmware versions (no specific version ranges or fixed version provided in the data)
  • +3 more
largehundreds of thousands of devices deployed, with likely tens of thousands of web interfaces internet-exposed
CVE-2025-28170
Grandstream Networks GXP1628 <=1.0.4.130 is vulnerable to Incorrect Access Control.

Grandstream Networks GXP1628 <=1.0.4.130 is vulnerable to Incorrect Access Control. The device is configured with directory listing enabled, allowing unauthorized access to sensitive directories and files.

NVD description · AI analysis pending
7.6<1% PoC
  • grandstream gxp1628 firmware
CVE-2025-28171
+1 in the same advisory: …28172
An issue in Grandstream UCM6510 v.1.0.20.52 and before allows a remote attacker to obtain sensitive information via the Login function at /cgi and /webrtccgi.

An issue in Grandstream UCM6510 v.1.0.20.52 and before allows a remote attacker to obtain sensitive information via the Login function at /cgi and /webrtccgi.

NVD description · AI analysis pending
6.5<1%
  • grandstream ucm6510 firmware
CVE-2024-32937
An os command injection vulnerability exists in the CWMP SelfDefinedTimeZone functionality of Grandstream GXP2135 1.0.9.129, 1.0.11.74 and 1.0.11.79.

An os command injection vulnerability exists in the CWMP SelfDefinedTimeZone functionality of Grandstream GXP2135 1.0.9.129, 1.0.11.74 and 1.0.11.79. A specially crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of malicious packets to trigger this vulnerability.

NVD description · AI analysis pending
9.826% PoC
  • grandstream gxp2135 firmware
CVE-2022-2070
+1 in the same advisory: …2025
In Grandstream GSD3710 in its 1.0.11.13 version, it's possible to overflow the stack since it doesn't check the param length before using the sscanf instruction.

In Grandstream GSD3710 in its 1.0.11.13 version, it's possible to overflow the stack since it doesn't check the param length before using the sscanf instruction. Because of that, an attacker could create a socket and connect with a remote IP:port by opening a shell and getting full access to the system. The exploit affects daemons dbmng and logsrv that are running on ports 8000 and 8001 by default.

NVD description · AI analysis pending
9.85%
  • grandstream gds3710 firmware
CVE-2021-37748
+1 in the same advisory: …37915
Multiple buffer overflows in the limited configuration shell (/sbin/gs_config) on Grandstream HT801 devices before 1.0.29 allow remote authenticated users to ex

Multiple buffer overflows in the limited configuration shell (/sbin/gs_config) on Grandstream HT801 devices before 1.0.29 allow remote authenticated users to execute arbitrary code as root via a crafted manage_if setting, thus bypassing the intended restrictions of this shell and taking full control of the device. There are default weak credentials that can be used to authenticate.

NVD description · AI analysis pending
8.87% PoC
  • grandstream ht801 firmware
CVE-2020-25218
+1 in the same advisory: …25217
Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allow Authentication Bypass in its administrative web interface.

Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allow Authentication Bypass in its administrative web interface.

NVD description · AI analysis pending
9.8
group max
2%
  • grandstream grp2612 firmware
  • grandstream grp2612p firmware
  • grandstream grp2612w firmware
  • +1 more
CVE-2020-5763
+3 in the same advisory: …5760 …5761 …5762
Grandstream HT800 series firmware version 1.0.17.5 and below contain a backdoor in the SSH service.

Grandstream HT800 series firmware version 1.0.17.5 and below contain a backdoor in the SSH service. An authenticated remote attacker can obtain a root shell by correctly answering a challenge prompt.

NVD description · AI analysis pending
8.8
group max
3% PoC
  • grandstream ht801 firmware
  • grandstream ht802 firmware
  • grandstream ht812 firmware
  • +1 more
CVE-2020-5757
+2 in the same advisory: …5759 …5758
Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP.

Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authenticated remote attacker can bypass command injection mitigations and execute commands as the root user by sending a crafted HTTP POST to the UCM's "New" HTTPS API.

NVD description · AI analysis pending
9.8
group max
7%
  • grandstream ucm6202 firmware
  • grandstream ucm6204 firmware
  • grandstream ucm6208 firmware
CVE-2020-5756
Grandstream GWN7000 firmware version 1.0.9.4 and below allows authenticated remote users to modify the system's crontab via undocumented API.

Grandstream GWN7000 firmware version 1.0.9.4 and below allows authenticated remote users to modify the system's crontab via undocumented API. An attacker can use this functionality to execute arbitrary OS commands on the router.

NVD description · AI analysis pending
8.82% PoC
  • grandstream gwn7000 firmware
CVE-2020-5738
+1 in the same advisory: …5739
Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker uploads a specially crafted tar

Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker uploads a specially crafted tar file to the HTTP /cgi-bin/upload_vpntar interface.

NVD description · AI analysis pending
8.85% PoC
  • grandstream gxp1610 firmware
  • grandstream gxp1615 firmware
  • grandstream gxp1620 firmware
  • +1 more
CVE-2020-5723
+3 in the same advisory: …5724 …5726 …5725
The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database.

The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database. This could allow an attacker to retrieve all passwords and possibly gain elevated privileges.

NVD description · AI analysis pending
9.8
group max
6% PoC
  • grandstream ucm6202 firmware
  • grandstream ucm6204 firmware
  • grandstream ucm6208 firmware
CVE-2020-5722
Unauthenticated SQL Injection to Root RCE in Grandstream UCM6200 Series IP PBX

CVE-2020-5722 is an unauthenticated SQL injection (CWE-89) in the HTTP interface of the Grandstream UCM6200 series IP PBX, triggered by sending a crafted HTTP request to the appliance's web service. On firmware versions before 1.0.19.20 an attacker can abuse it to execute arbitrary shell commands as root on the appliance, and on versions before 1.0.20.17 it can also be used to inject HTML into the device's password recovery emails. Any organization running UCM6200-series firmware prior to 1.0.20.17 is affected, with internet-exposed PBX appliances at the greatest risk. The flaw carries a critical CVSS 3.1 score of 9.8 and a top-percentile EPSS probability (84.4%) of exploitation within 30 days; public proof-of-concept exploits exist, CISA added it to the Known Exploited Vulnerabilities catalog on 2022-01-28, and related reporting on the Hoaxcalls botnet expanding its target list is consistent with in-the-wild abuse of these devices.

Do: Upgrade UCM6200-series firmware to version 1.0.20.17 or later per Grandstream's instructions, which addresses both impact branches; devices on versions before 1.0.19.20 are exposed to unauthenticated root command execution and should be patched immediately. Until patched, restrict the appliance's HTTP interface to trusted management networks and review internet-exposed units for signs of compromise, since CISA has confirmed exploitation.

9.884% KEV PoC ×3
  • Grandstream Networks UCM6200 series IP PBX firmware all versions before 1.0.20.17 (root shell command execution via the SQL injection in versions before 1.0.19.20; HTML injection in password recovery emails in ve
large≈10,000–100,000 internet-exposed UCM6200 appliances (order-of-magnitude estimate)
CVE-2018-17565
+2 in the same advisory: …17564 …17563
Shell Metacharacter Injection in the SSH configuration interface on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to execute arbitrary system comma

Shell Metacharacter Injection in the SSH configuration interface on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to execute arbitrary system commands and gain a root shell.

NVD description · AI analysis pending
9.8
group max
2%
  • grandstream gxp1610 firmware
  • grandstream gxp1615 firmware
  • grandstream gxp1620 firmware
  • +1 more
CVE-2019-10662
+1 in the same advisory: …10663
Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the backupUCMConfig file-bac

Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the backupUCMConfig file-backup parameter to the /cgi? URI.

NVD description · AI analysis pending
8.844%
  • grandstream ucm6204 firmware
CVE-2019-10661
+1 in the same advisory: …10660
On Grandstream GXV3611IR_HD before 1.0.3.23 devices, the root account lacks a password.

On Grandstream GXV3611IR_HD before 1.0.3.23 devices, the root account lacks a password.

NVD description · AI analysis pending
9.8
group max
2%
  • grandstream gxv3611ir hd firmware
CVE-2019-10659
Grandstream GXV3370 before 1.0.1.41 and WP820 before 1.0.3.6 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in a /m

Grandstream GXV3370 before 1.0.1.41 and WP820 before 1.0.3.6 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in a /manager?action=getlogcat priority field.

NVD description · AI analysis pending
8.83%
  • grandstream gxv3370 firmware
  • grandstream wp820 firmware
CVE-2019-10658
+1 in the same advisory: …10657
Grandstream GWN7610 before 1.0.8.18 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filename in a /ubus/contr

Grandstream GWN7610 before 1.0.8.18 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filename in a /ubus/controller.icc.update_nds_webroot_from_tmp update_nds_webroot_from_tmp API call.

NVD description · AI analysis pending
8.8
group max
3%
  • grandstream gwn7610 firmware
CVE-2019-10656
Grandstream GWN7000 before 1.0.6.32 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filename in a /ubus/uci.a

Grandstream GWN7000 before 1.0.6.32 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filename in a /ubus/uci.apply update_nds_webroot_from_tmp API call.

NVD description · AI analysis pending
8.84%
  • grandstream gwn7000 firmware
CVE-2019-10655
Grandstream GAC2500 1.0.3.35, GXP2200 1.0.3.27, GVC3202 1.0.3.51, GXV3275 before 1.0.3.219 Beta, and GXV3240 before 1.0.3.219 Beta devices allow unauthenticated

Grandstream GAC2500 1.0.3.35, GXP2200 1.0.3.27, GVC3202 1.0.3.51, GXV3275 before 1.0.3.219 Beta, and GXV3240 before 1.0.3.219 Beta devices allow unauthenticated remote code execution via shell metacharacters in a /manager?action=getlogcat priority field, in conjunction with a buffer overflow (via the phonecookie cookie) to overwrite a data structure and consequently bypass authentication. This can be exploited remotely or via CSRF because the cookie can be placed in an Accept HTTP header in an XMLHttpRequest call to lighttpd.

NVD description · AI analysis pending
9.815% PoC ×3
  • grandstream gac2500 firmware
  • grandstream gvc3202 firmware
  • grandstream gxv3275 firmware
  • +1 more
CVE-2017-16565
+2 in the same advisory: …16563 …16564
Cross-Site Request Forgery (CSRF) in /cgi-bin/login on Vonage (Grandstream) HT802 devices allows attackers to authenticate a user via the login screen using the

Cross-Site Request Forgery (CSRF) in /cgi-bin/login on Vonage (Grandstream) HT802 devices allows attackers to authenticate a user via the login screen using the default password of 123 and submit arbitrary requests.

NVD description · AI analysis pending
8.8
group max
<1% PoC
  • grandstream ht802 firmware
CVE-2016-1518
+2 in the same advisory: …1520 …1519
The auto-provisioning mechanism in the Grandstream Wave app 1.0.1.26 and earlier for Android and Grandstream Video IP phones allows man-in-the-middle attackers

The auto-provisioning mechanism in the Grandstream Wave app 1.0.1.26 and earlier for Android and Grandstream Video IP phones allows man-in-the-middle attackers to spoof provisioning data and consequently modify device functionality, obtain sensitive information from system logs, and have unspecified other impact by leveraging failure to use an HTTPS session for downloading configuration files from http://fm.grandstream.com/gs/.

NVD description · AI analysis pending
8.1
group max
2%
  • grandstream wave