Vulnerabilities
44 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-2329 | Unauthenticated RCE via stack buffer overflow in Grandstream GXP1600-series VoIP phones An unauthenticated stack-based buffer overflow (CWE-121) exists in the HTTP API endpoint /cgi-bin/api.values.get on Grandstream GXP1600-series VoIP desk phones. A remote attacker who can reach the phone's web API can send a crafted request to this endpoint with no credentials, overflowing a stack buffer and executing code with root privileges on the device. Full root control gives attackers a stealthy network foothold inside the victim network, with the potential to intercept calls or pivot to other systems. All six models in the series are affected: GXP1610, GXP1615, GXP1620, GXP1625, GXP1628, and GXP1630. No public proof-of-concept or confirmed in-the-wild exploitation is known yet, but EPSS assigns a 40% probability of exploitation within 30 days (99th percentile), so rapid weaponization is likely. Do: Upgrade all GXP1600-series phones (GXP1610/1615/1620/1625/1628/1630) to the latest firmware available from Grandstream, per the vendor advisory. Until patched, do not expose the phones' HTTP management interface to the internet, restrict access to it from untrusted networks, and review web server logs for requests to /cgi-bin/api.values.get as a sign of probing or compromise. Also check affected devices for indicators of exploitation such as unexpected call behavior, call interception, or unusual outbound traffic. | 9.3 | 40% |
| largehundreds of thousands of devices deployed, with likely tens of thousands of web interfaces internet-exposed | ||
| CVE-2025-28170 | Grandstream Networks GXP1628 <=1.0.4.130 is vulnerable to Incorrect Access Control. Grandstream Networks GXP1628 <=1.0.4.130 is vulnerable to Incorrect Access Control. The device is configured with directory listing enabled, allowing unauthorized access to sensitive directories and files. NVD description · AI analysis pending | 7.6 | <1% | PoC |
| — | |
| CVE-2025-28171 +1 in the same advisory: …28172 | An issue in Grandstream UCM6510 v.1.0.20.52 and before allows a remote attacker to obtain sensitive information via the Login function at /cgi and /webrtccgi. An issue in Grandstream UCM6510 v.1.0.20.52 and before allows a remote attacker to obtain sensitive information via the Login function at /cgi and /webrtccgi. NVD description · AI analysis pending | 6.5 | <1% |
| — | ||
| CVE-2024-32937 | An os command injection vulnerability exists in the CWMP SelfDefinedTimeZone functionality of Grandstream GXP2135 1.0.9.129, 1.0.11.74 and 1.0.11.79. An os command injection vulnerability exists in the CWMP SelfDefinedTimeZone functionality of Grandstream GXP2135 1.0.9.129, 1.0.11.74 and 1.0.11.79. A specially crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of malicious packets to trigger this vulnerability. NVD description · AI analysis pending | 9.8 | 26% | PoC |
| — | |
| CVE-2022-2070 +1 in the same advisory: …2025 | In Grandstream GSD3710 in its 1.0.11.13 version, it's possible to overflow the stack since it doesn't check the param length before using the sscanf instruction. In Grandstream GSD3710 in its 1.0.11.13 version, it's possible to overflow the stack since it doesn't check the param length before using the sscanf instruction. Because of that, an attacker could create a socket and connect with a remote IP:port by opening a shell and getting full access to the system. The exploit affects daemons dbmng and logsrv that are running on ports 8000 and 8001 by default. NVD description · AI analysis pending | 9.8 | 5% |
| — | ||
| CVE-2021-37748 +1 in the same advisory: …37915 | Multiple buffer overflows in the limited configuration shell (/sbin/gs_config) on Grandstream HT801 devices before 1.0.29 allow remote authenticated users to ex Multiple buffer overflows in the limited configuration shell (/sbin/gs_config) on Grandstream HT801 devices before 1.0.29 allow remote authenticated users to execute arbitrary code as root via a crafted manage_if setting, thus bypassing the intended restrictions of this shell and taking full control of the device. There are default weak credentials that can be used to authenticate. NVD description · AI analysis pending | 8.8 | 7% | PoC |
| — | |
| CVE-2020-25218 +1 in the same advisory: …25217 | Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allow Authentication Bypass in its administrative web interface. Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allow Authentication Bypass in its administrative web interface. NVD description · AI analysis pending | 9.8 group max | 2% |
| — | ||
| CVE-2020-5763 | Grandstream HT800 series firmware version 1.0.17.5 and below contain a backdoor in the SSH service. Grandstream HT800 series firmware version 1.0.17.5 and below contain a backdoor in the SSH service. An authenticated remote attacker can obtain a root shell by correctly answering a challenge prompt. NVD description · AI analysis pending | 8.8 group max | 3% | PoC |
| — | |
| CVE-2020-5757 | Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authenticated remote attacker can bypass command injection mitigations and execute commands as the root user by sending a crafted HTTP POST to the UCM's "New" HTTPS API. NVD description · AI analysis pending | 9.8 group max | 7% |
| — | ||
| CVE-2020-5756 | Grandstream GWN7000 firmware version 1.0.9.4 and below allows authenticated remote users to modify the system's crontab via undocumented API. Grandstream GWN7000 firmware version 1.0.9.4 and below allows authenticated remote users to modify the system's crontab via undocumented API. An attacker can use this functionality to execute arbitrary OS commands on the router. NVD description · AI analysis pending | 8.8 | 2% | PoC |
| — | |
| CVE-2020-5738 +1 in the same advisory: …5739 | Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker uploads a specially crafted tar Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker uploads a specially crafted tar file to the HTTP /cgi-bin/upload_vpntar interface. NVD description · AI analysis pending | 8.8 | 5% | PoC |
| — | |
| CVE-2020-5723 | The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database. The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database. This could allow an attacker to retrieve all passwords and possibly gain elevated privileges. NVD description · AI analysis pending | 9.8 group max | 6% | PoC |
| — | |
| CVE-2020-5722 | Unauthenticated SQL Injection to Root RCE in Grandstream UCM6200 Series IP PBX CVE-2020-5722 is an unauthenticated SQL injection (CWE-89) in the HTTP interface of the Grandstream UCM6200 series IP PBX, triggered by sending a crafted HTTP request to the appliance's web service. On firmware versions before 1.0.19.20 an attacker can abuse it to execute arbitrary shell commands as root on the appliance, and on versions before 1.0.20.17 it can also be used to inject HTML into the device's password recovery emails. Any organization running UCM6200-series firmware prior to 1.0.20.17 is affected, with internet-exposed PBX appliances at the greatest risk. The flaw carries a critical CVSS 3.1 score of 9.8 and a top-percentile EPSS probability (84.4%) of exploitation within 30 days; public proof-of-concept exploits exist, CISA added it to the Known Exploited Vulnerabilities catalog on 2022-01-28, and related reporting on the Hoaxcalls botnet expanding its target list is consistent with in-the-wild abuse of these devices. Do: Upgrade UCM6200-series firmware to version 1.0.20.17 or later per Grandstream's instructions, which addresses both impact branches; devices on versions before 1.0.19.20 are exposed to unauthenticated root command execution and should be patched immediately. Until patched, restrict the appliance's HTTP interface to trusted management networks and review internet-exposed units for signs of compromise, since CISA has confirmed exploitation. | 9.8 | 84% | KEV PoC ×3 |
| large≈10,000–100,000 internet-exposed UCM6200 appliances (order-of-magnitude estimate) | |
| CVE-2018-17565 | Shell Metacharacter Injection in the SSH configuration interface on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to execute arbitrary system comma Shell Metacharacter Injection in the SSH configuration interface on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to execute arbitrary system commands and gain a root shell. NVD description · AI analysis pending | 9.8 group max | 2% |
| — | ||
| CVE-2019-10662 +1 in the same advisory: …10663 | Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the backupUCMConfig file-bac Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the backupUCMConfig file-backup parameter to the /cgi? URI. NVD description · AI analysis pending | 8.8 | 44% |
| — | ||
| CVE-2019-10661 +1 in the same advisory: …10660 | On Grandstream GXV3611IR_HD before 1.0.3.23 devices, the root account lacks a password. On Grandstream GXV3611IR_HD before 1.0.3.23 devices, the root account lacks a password. NVD description · AI analysis pending | 9.8 group max | 2% |
| — | ||
| CVE-2019-10659 | Grandstream GXV3370 before 1.0.1.41 and WP820 before 1.0.3.6 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in a /m Grandstream GXV3370 before 1.0.1.41 and WP820 before 1.0.3.6 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in a /manager?action=getlogcat priority field. NVD description · AI analysis pending | 8.8 | 3% |
| — | ||
| CVE-2019-10658 +1 in the same advisory: …10657 | Grandstream GWN7610 before 1.0.8.18 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filename in a /ubus/contr Grandstream GWN7610 before 1.0.8.18 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filename in a /ubus/controller.icc.update_nds_webroot_from_tmp update_nds_webroot_from_tmp API call. NVD description · AI analysis pending | 8.8 group max | 3% |
| — | ||
| CVE-2019-10656 | Grandstream GWN7000 before 1.0.6.32 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filename in a /ubus/uci.a Grandstream GWN7000 before 1.0.6.32 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filename in a /ubus/uci.apply update_nds_webroot_from_tmp API call. NVD description · AI analysis pending | 8.8 | 4% |
| — | ||
| CVE-2019-10655 | Grandstream GAC2500 1.0.3.35, GXP2200 1.0.3.27, GVC3202 1.0.3.51, GXV3275 before 1.0.3.219 Beta, and GXV3240 before 1.0.3.219 Beta devices allow unauthenticated Grandstream GAC2500 1.0.3.35, GXP2200 1.0.3.27, GVC3202 1.0.3.51, GXV3275 before 1.0.3.219 Beta, and GXV3240 before 1.0.3.219 Beta devices allow unauthenticated remote code execution via shell metacharacters in a /manager?action=getlogcat priority field, in conjunction with a buffer overflow (via the phonecookie cookie) to overwrite a data structure and consequently bypass authentication. This can be exploited remotely or via CSRF because the cookie can be placed in an Accept HTTP header in an XMLHttpRequest call to lighttpd. NVD description · AI analysis pending | 9.8 | 15% | PoC ×3 |
| — | |
| CVE-2017-16565 | Cross-Site Request Forgery (CSRF) in /cgi-bin/login on Vonage (Grandstream) HT802 devices allows attackers to authenticate a user via the login screen using the Cross-Site Request Forgery (CSRF) in /cgi-bin/login on Vonage (Grandstream) HT802 devices allows attackers to authenticate a user via the login screen using the default password of 123 and submit arbitrary requests. NVD description · AI analysis pending | 8.8 group max | <1% | PoC |
| — | |
| CVE-2016-1518 | The auto-provisioning mechanism in the Grandstream Wave app 1.0.1.26 and earlier for Android and Grandstream Video IP phones allows man-in-the-middle attackers The auto-provisioning mechanism in the Grandstream Wave app 1.0.1.26 and earlier for Android and Grandstream Video IP phones allows man-in-the-middle attackers to spoof provisioning data and consequently modify device functionality, obtain sensitive information from system logs, and have unspecified other impact by leveraging failure to use an HTTPS session for downloading configuration files from http://fm.grandstream.com/gs/. NVD description · AI analysis pending | 8.1 group max | 2% |
| — |