Skip to content
Noroxi

Grandstream records

57 published records for vendor grandstream.

All records

57 records
  • The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request.

    CriticalCVSS 9.8KEVWeaponizedEPSS 84%

    grandstream · ucm6200 firmwareMar 23, 2020

  • Grandstream GXP1600 VoIP Phones - Unauthenticated stack buffer overflow

    CriticalCVSS 9.3WeaponizedEPSS 41%

    grandstream · gxp1610 firmwareFeb 18, 2026

  • Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the back

    HighCVSS 8.8No exploitEPSS 44%

    grandstream · ucm6204 firmwareMar 30, 2019

  • An os command injection vulnerability exists in the CWMP SelfDefinedTimeZone functionality of Grandstream GXP2135 1.0.9.129, 1.0.11.74 and 1

    CriticalCVSS 9.8No exploitEPSS 26%

    grandstream · gxp2135 firmwareJul 3, 2024

  • Grandstream GAC2500 1.0.3.35, GXP2200 1.0.3.27, GVC3202 1.0.3.51, GXV3275 before 1.0.3.219 Beta, and GXV3240 before 1.0.3.219 Beta devices a

    CriticalCVSS 9.8WeaponizedEPSS 15%

    grandstream · gac2500 firmwareMar 30, 2019

  • Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to conduct SQL injection attacks via the sord parameter in a l

    HighCVSS 8.8No exploitEPSS 28%

    grandstream · ucm6204 firmwareMar 30, 2019

  • Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP.

    CriticalCVSS 9.8No exploitEPSS 7%

    grandstream · ucm6202 firmwareJul 17, 2020

  • The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database.

    CriticalCVSS 9.8WeaponizedEPSS 6%

    grandstream · ucm6202 firmwareMar 30, 2020

  • Grandstream GSD3710 Stack-based Buffer Overflow

    CriticalCVSS 9.8Proof of conceptEPSS 6%

    grandstream · gds3710 firmwareSep 23, 2022

  • Grandstream GSD3710 Stack-based Buffer Overflow

    CriticalCVSS 9.8Proof of conceptEPSS 5%

    grandstream · gds3710 firmwareSep 23, 2022

  • Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P, GXV3651FHD, GXV3662HD, GXV3615WP_HD, GXV3500, and possibly ot

    CriticalCVSS 10.0No exploitEPSS 3%

    grandstream · gxv3501 firmwareDec 11, 2019

  • Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via SSH.

    CriticalCVSS 9.8No exploitEPSS 3%

    grandstream · ucm6202 firmwareJul 17, 2020

  • Shell Metacharacter Injection in the SSH configuration interface on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to execute ar

    CriticalCVSS 9.8No exploitEPSS 2%

    grandstream · gxp1610 firmwareApr 1, 2019

  • Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allow Authentication Bypass in its administrative web interface.

    CriticalCVSS 9.8No exploitEPSS 2%

    grandstream · grp2612 firmwareMar 29, 2021

  • On Grandstream GXV3611IR_HD before 1.0.3.23 devices, the root account lacks a password.

    CriticalCVSS 9.8No exploitEPSS 2%

    grandstream · gxv3611ir hd firmwareMar 30, 2019

  • A Malformed Input String to /cgi-bin/delete_CA on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to delete configuration paramet

    CriticalCVSS 9.8No exploitEPSS 2%

    grandstream · gxp1610 firmwareApr 1, 2019

  • Multiple buffer overflows in the limited configuration shell (/sbin/gs_config) on Grandstream HT801 devices before 1.0.29 allow remote authe

    HighCVSS 8.8Proof of conceptEPSS 7%

    grandstream · ht801 firmwareOct 28, 2021

  • CVE-2020-5738
    37Monitor

    Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker uploads a s

    HighCVSS 8.8No exploitEPSS 5%

    grandstream · gxp1610 firmwareApr 14, 2020

  • CVE-2020-5739
    37Monitor

    Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker adds an Ope

    HighCVSS 8.8No exploitEPSS 5%

    grandstream · gxp1610 firmwareApr 14, 2020

  • CVE-2020-5758
    36Monitor

    Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP.

    HighCVSS 8.8No exploitEPSS 4%

    grandstream · ucm6202 firmwareJul 17, 2020

  • Grandstream GWN7000 before 1.0.6.32 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filen

    HighCVSS 8.8No exploitEPSS 4%

    grandstream · gwn7000 firmwareMar 30, 2019

  • CVE-2020-5763
    36Monitor

    Grandstream HT800 series firmware version 1.0.17.5 and below contain a backdoor in the SSH service.

    HighCVSS 8.8No exploitEPSS 3%

    grandstream · ht801 firmwareJul 29, 2020

  • Grandstream GWN7610 before 1.0.8.18 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filen

    HighCVSS 8.8No exploitEPSS 3%

    grandstream · gwn7610 firmwareMar 30, 2019

  • Grandstream GXV3611IR_HD before 1.0.3.23 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the

    HighCVSS 8.8No exploitEPSS 3%

    grandstream · gxv3611ir hd firmwareMar 30, 2019

  • Grandstream GXV3370 before 1.0.1.41 and WP820 before 1.0.3.6 devices allow remote authenticated users to execute arbitrary code via shell me

    HighCVSS 8.8No exploitEPSS 3%

    grandstream · gxv3370 firmwareMar 30, 2019