ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Bug in widely used VoIP phones allows stealthy network footholds, call interception (CVE-2026-2329)

criticalVulnerabilityimportance 60CVE-2026-2329

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-2329
Unauthenticated RCE via stack buffer overflow in Grandstream GXP1600-series VoIP phones

An unauthenticated stack-based buffer overflow (CWE-121) exists in the HTTP API endpoint /cgi-bin/api.values.get on Grandstream GXP1600-series VoIP desk phones. A remote attacker who can reach the phone's web API can send a crafted request to this endpoint with no credentials, overflowing a stack buffer and executing code with root privileges on the device. Full root control gives attackers a stealthy network foothold inside the victim network, with the potential to intercept calls or pivot to other systems. All six models in the series are affected: GXP1610, GXP1615, GXP1620, GXP1625, GXP1628, and GXP1630. No public proof-of-concept or confirmed in-the-wild exploitation is known yet, but EPSS assigns a 40% probability of exploitation within 30 days (99th percentile), so rapid weaponization is likely.

Do: Upgrade all GXP1600-series phones (GXP1610/1615/1620/1625/1628/1630) to the latest firmware available from Grandstream, per the vendor advisory. Until patched, do not expose the phones' HTTP management interface to the internet, restrict access to it from untrusted networks, and review web server logs for requests to /cgi-bin/api.values.get as a sign of probing or compromise. Also check affected devices for indicators of exploitation such as unexpected call behavior, call interception, or unusual outbound traffic.

9.340%
  • Grandstream GXP1610 firmware All firmware versions (no specific version ranges or fixed version provided in the data)
  • Grandstream GXP1615 firmware All firmware versions (no specific version ranges or fixed version provided in the data)
  • Grandstream GXP1620 firmware All firmware versions (no specific version ranges or fixed version provided in the data)
  • +3 more
largehundreds of thousands of devices deployed, with likely tens of thousands of web interfaces internet-exposed
Full article408 words · extracted from helpnetsecurity.com · click to collapse

A critical security vulnerability (CVE-2026-2329) in Grandstream VoIP phones could let hackers remotely take full control of the devices and even intercept calls, Rapid7 researchers discovered.

Grandstream CVE-2026-2329

“The vulnerability is present in the device’s web-based API service, and is accessible in a default configuration,” Rapid7 researcher Stephen Fewer noted.

The risks related to CVE-2026-2329 exploitation

CVE-2026-2329 stems from improper bounds checking in a web management endpoint.

An attacker can send a specially crafted request to the device that triggers a buffer overflow condition, potentially enabling unauthenticated attackers to remotely execute code with root privileges on a vulnerable device.

Because the flaw does not require authentication, it can be exploited without valid credentials if the management interface is reachable (either directly, or from somewhere else inside the network).

Rapid7 has developed Metasploit exploit modules to demonstrate how attackers may leverage this vulnerability to:

  • Remotely execute code with root privileges on a vulnerable device
  • Gather credentials (e.g., local user and SIP accounts) stored on the device

“Finally, we can leverage our RCE capabilities to reconfigure the target device to use a malicious SIP proxy [a server that routes Session Initiation Protocol messages between devices], allowing an attacker to transparently intercept phone calls to and from the device, and eavesdrop on the audio,” Fewer explained.

What to do?

CVE-2026-2329 affects the entire Grandstream GXP1600 series: GXP1610, GXP1615, GXP1620, GXP1625, GXP1628, and GXP1630.

More specifically, the flaw affects firmware versions 1.0.7.79 and earlier, and has been fixed in v1.0.7.81.

This line of VoIP desk phones is widely used in small offices and corporate deployments. These devices are often deployed on internal networks, but are sometimes exposed to the internet for remote administration.

Because detailed technical information about the flaw is publicly available and Metasploit exploit modules have been released, organizations using these VoIP phones are strongly urged to apply the updated firmware as soon as possible.

While exploitation requires knowledge and skill, the vulnerability “lowers the barrier in a way that should concern anyone operating these devices in exposed or lightly-segmented environments,” said Douglas McKee, Director of Vulnerability Intelligence at Rapid7.

He also pointed out that the main risk lies in the potential for long-term, covert access, as VoIP phones are typically trusted by default within corporate environments and often remain in service for years after deployment with little additional scrutiny.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/02/19/grandstream-voip-phones-vulnerability-cve-2026-2329/