Записи Grandstream
57 опубликованных записей вендора grandstream.
Профиль для исследователя
- Попали в KEV
- 1 · 1,8 %
- С эксплойтом
- 5 · 8,8 %
- Pre-auth RCE
- 7
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- 676 дн.
Повторяющиеся классы
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')13
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')6
- CWE-121 Stack-based Buffer Overflow3
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-489 Active Debug Code2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
57 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
94Срочно | CVE-2020-5722Готовый эксплойт | The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request.grandstream · ucm6200 firmware · CWE-89 | Критическая9,8 | KEV | 84,4 % | 23 мар. 2020 г. |
49В плане | CVE-2026-2329Готовый эксплойт | Grandstream GXP1600 VoIP Phones - Unauthenticated stack buffer overflowgrandstream · gxp1610 firmware · CWE-121 | Критическая9,3 | — | 40,6 % | 18 февр. 2026 г. |
48В плане | CVE-2019-10662Эксплойта нет | Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the backgrandstream · ucm6204 firmware · CWE-78 | Высокая8,8 | — | 43,9 % | 30 мар. 2019 г. |
47В плане | CVE-2024-32937Эксплойта нет | An os command injection vulnerability exists in the CWMP SelfDefinedTimeZone functionality of Grandstream GXP2135 1.0.9.129, 1.0.11.74 and 1grandstream · gxp2135 firmware · CWE-78 | Критическая9,8 | — | 26,3 % | 3 июл. 2024 г. |
44В плане | CVE-2019-10655Готовый эксплойт | Grandstream GAC2500 1.0.3.35, GXP2200 1.0.3.27, GVC3202 1.0.3.51, GXV3275 before 1.0.3.219 Beta, and GXV3240 before 1.0.3.219 Beta devices agrandstream · gac2500 firmware · CWE-78 | Критическая9,8 | — | 15,5 % | 30 мар. 2019 г. |
43В плане | CVE-2019-10663Эксплойта нет | Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to conduct SQL injection attacks via the sord parameter in a lgrandstream · ucm6204 firmware · CWE-89 | Высокая8,8 | — | 27,9 % | 30 мар. 2019 г. |
41В плане | CVE-2020-5757Эксплойта нет | Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP.grandstream · ucm6202 firmware · CWE-78 | Критическая9,8 | — | 6,9 % | 17 июл. 2020 г. |
41В плане | CVE-2020-5723Готовый эксплойт | The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database.grandstream · ucm6202 firmware · CWE-312 | Критическая9,8 | — | 5,9 % | 30 мар. 2020 г. |
41В плане | CVE-2022-2070Proof of concept | Grandstream GSD3710 Stack-based Buffer Overflowgrandstream · gds3710 firmware · CWE-121 | Критическая9,8 | — | 5,7 % | 23 сент. 2022 г. |
41В плане | CVE-2022-2025Proof of concept | Grandstream GSD3710 Stack-based Buffer Overflowgrandstream · gds3710 firmware · CWE-121 | Критическая9,8 | — | 5,3 % | 23 сент. 2022 г. |
41В плане | CVE-2013-3542Эксплойта нет | Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P, GXV3651FHD, GXV3662HD, GXV3615WP_HD, GXV3500, and possibly otgrandstream · gxv3501 firmware · CWE-798 | Критическая10,0 | — | 2,6 % | 11 дек. 2019 г. |
40В плане | CVE-2020-5759Эксплойта нет | Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via SSH.grandstream · ucm6202 firmware · CWE-78 | Критическая9,8 | — | 3,2 % | 17 июл. 2020 г. |
40В плане | CVE-2018-17565Эксплойта нет | Shell Metacharacter Injection in the SSH configuration interface on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to execute argrandstream · gxp1610 firmware · CWE-78 | Критическая9,8 | — | 1,9 % | 1 апр. 2019 г. |
40В плане | CVE-2020-25218Эксплойта нет | Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allow Authentication Bypass in its administrative web interface.grandstream · grp2612 firmware · CWE-306 | Критическая9,8 | — | 1,8 % | 29 мар. 2021 г. |
40В плане | CVE-2019-10661Эксплойта нет | On Grandstream GXV3611IR_HD before 1.0.3.23 devices, the root account lacks a password.grandstream · gxv3611ir hd firmware · CWE-287 | Критическая9,8 | — | 1,8 % | 30 мар. 2019 г. |
39Наблюдать | CVE-2018-17564Эксплойта нет | A Malformed Input String to /cgi-bin/delete_CA on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to delete configuration parametgrandstream · gxp1610 firmware | Критическая9,8 | — | 1,6 % | 1 апр. 2019 г. |
37Наблюдать | CVE-2021-37748Proof of concept | Multiple buffer overflows in the limited configuration shell (/sbin/gs_config) on Grandstream HT801 devices before 1.0.29 allow remote authegrandstream · ht801 firmware · CWE-787 | Высокая8,8 | — | 7,4 % | 28 окт. 2021 г. |
37Наблюдать | CVE-2020-5738Эксплойта нет | Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker uploads a sgrandstream · gxp1610 firmware · CWE-59 | Высокая8,8 | — | 5,4 % | 14 апр. 2020 г. |
37Наблюдать | CVE-2020-5739Эксплойта нет | Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker adds an Opegrandstream · gxp1610 firmware · CWE-94 | Высокая8,8 | — | 5,3 % | 14 апр. 2020 г. |
36Наблюдать | CVE-2020-5758Эксплойта нет | Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP.grandstream · ucm6202 firmware · CWE-78 | Высокая8,8 | — | 4,4 % | 17 июл. 2020 г. |
36Наблюдать | CVE-2019-10656Эксплойта нет | Grandstream GWN7000 before 1.0.6.32 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filengrandstream · gwn7000 firmware · CWE-78 | Высокая8,8 | — | 3,9 % | 30 мар. 2019 г. |
36Наблюдать | CVE-2020-5763Эксплойта нет | Grandstream HT800 series firmware version 1.0.17.5 and below contain a backdoor in the SSH service.grandstream · ht801 firmware · CWE-489 | Высокая8,8 | — | 2,7 % | 29 июл. 2020 г. |
36Наблюдать | CVE-2019-10658Эксплойта нет | Grandstream GWN7610 before 1.0.8.18 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filengrandstream · gwn7610 firmware · CWE-78 | Высокая8,8 | — | 2,6 % | 30 мар. 2019 г. |
36Наблюдать | CVE-2019-10660Эксплойта нет | Grandstream GXV3611IR_HD before 1.0.3.23 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the grandstream · gxv3611ir hd firmware · CWE-78 | Высокая8,8 | — | 2,6 % | 30 мар. 2019 г. |
36Наблюдать | CVE-2019-10659Эксплойта нет | Grandstream GXV3370 before 1.0.1.41 and WP820 before 1.0.3.6 devices allow remote authenticated users to execute arbitrary code via shell megrandstream · gxv3370 firmware · CWE-78 | Высокая8,8 | — | 2,6 % | 30 мар. 2019 г. |
- CVE-2020-572294Срочно
The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 84 %grandstream · ucm6200 firmware23 мар. 2020 г.
- CVE-2026-232949В плане
Grandstream GXP1600 VoIP Phones - Unauthenticated stack buffer overflow
КритическаяCVSS 9,3Готовый эксплойтEPSS 41 %grandstream · gxp1610 firmware18 февр. 2026 г.
- CVE-2019-1066248В плане
Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the back
ВысокаяCVSS 8,8Эксплойта нетEPSS 44 %grandstream · ucm6204 firmware30 мар. 2019 г.
- CVE-2024-3293747В плане
An os command injection vulnerability exists in the CWMP SelfDefinedTimeZone functionality of Grandstream GXP2135 1.0.9.129, 1.0.11.74 and 1
КритическаяCVSS 9,8Эксплойта нетEPSS 26 %grandstream · gxp2135 firmware3 июл. 2024 г.
- CVE-2019-1065544В плане
Grandstream GAC2500 1.0.3.35, GXP2200 1.0.3.27, GVC3202 1.0.3.51, GXV3275 before 1.0.3.219 Beta, and GXV3240 before 1.0.3.219 Beta devices a
КритическаяCVSS 9,8Готовый эксплойтEPSS 15 %grandstream · gac2500 firmware30 мар. 2019 г.
- CVE-2019-1066343В плане
Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to conduct SQL injection attacks via the sord parameter in a l
ВысокаяCVSS 8,8Эксплойта нетEPSS 28 %grandstream · ucm6204 firmware30 мар. 2019 г.
- CVE-2020-575741В плане
Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP.
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %grandstream · ucm6202 firmware17 июл. 2020 г.
- CVE-2020-572341В плане
The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database.
КритическаяCVSS 9,8Готовый эксплойтEPSS 6 %grandstream · ucm6202 firmware30 мар. 2020 г.
- CVE-2022-207041В плане
Grandstream GSD3710 Stack-based Buffer Overflow
КритическаяCVSS 9,8Proof of conceptEPSS 6 %grandstream · gds3710 firmware23 сент. 2022 г.
- CVE-2022-202541В плане
Grandstream GSD3710 Stack-based Buffer Overflow
КритическаяCVSS 9,8Proof of conceptEPSS 5 %grandstream · gds3710 firmware23 сент. 2022 г.
- CVE-2013-354241В плане
Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P, GXV3651FHD, GXV3662HD, GXV3615WP_HD, GXV3500, and possibly ot
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %grandstream · gxv3501 firmware11 дек. 2019 г.
- CVE-2020-575940В плане
Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via SSH.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %grandstream · ucm6202 firmware17 июл. 2020 г.
- CVE-2018-1756540В плане
Shell Metacharacter Injection in the SSH configuration interface on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to execute ar
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %grandstream · gxp1610 firmware1 апр. 2019 г.
- CVE-2020-2521840В плане
Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allow Authentication Bypass in its administrative web interface.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %grandstream · grp2612 firmware29 мар. 2021 г.
- CVE-2019-1066140В плане
On Grandstream GXV3611IR_HD before 1.0.3.23 devices, the root account lacks a password.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %grandstream · gxv3611ir hd firmware30 мар. 2019 г.
- CVE-2018-1756439Наблюдать
A Malformed Input String to /cgi-bin/delete_CA on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to delete configuration paramet
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %grandstream · gxp1610 firmware1 апр. 2019 г.
- CVE-2021-3774837Наблюдать
Multiple buffer overflows in the limited configuration shell (/sbin/gs_config) on Grandstream HT801 devices before 1.0.29 allow remote authe
ВысокаяCVSS 8,8Proof of conceptEPSS 7 %grandstream · ht801 firmware28 окт. 2021 г.
- CVE-2020-573837Наблюдать
Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker uploads a s
ВысокаяCVSS 8,8Эксплойта нетEPSS 5 %grandstream · gxp1610 firmware14 апр. 2020 г.
- CVE-2020-573937Наблюдать
Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker adds an Ope
ВысокаяCVSS 8,8Эксплойта нетEPSS 5 %grandstream · gxp1610 firmware14 апр. 2020 г.
- CVE-2020-575836Наблюдать
Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP.
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %grandstream · ucm6202 firmware17 июл. 2020 г.
- CVE-2019-1065636Наблюдать
Grandstream GWN7000 before 1.0.6.32 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filen
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %grandstream · gwn7000 firmware30 мар. 2019 г.
- CVE-2020-576336Наблюдать
Grandstream HT800 series firmware version 1.0.17.5 and below contain a backdoor in the SSH service.
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %grandstream · ht801 firmware29 июл. 2020 г.
- CVE-2019-1065836Наблюдать
Grandstream GWN7610 before 1.0.8.18 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filen
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %grandstream · gwn7610 firmware30 мар. 2019 г.
- CVE-2019-1066036Наблюдать
Grandstream GXV3611IR_HD before 1.0.3.23 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %grandstream · gxv3611ir hd firmware30 мар. 2019 г.
- CVE-2019-1065936Наблюдать
Grandstream GXV3370 before 1.0.1.41 and WP820 before 1.0.3.6 devices allow remote authenticated users to execute arbitrary code via shell me
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %grandstream · gxv3370 firmware30 мар. 2019 г.