Перейти к содержимому
Noroxi

Записи Grandstream

57 опубликованных записей вендора grandstream.

Профиль для исследователя

Попали в KEV
1 · 1,8 %
С эксплойтом
5 · 8,8 %
Pre-auth RCE
7
С записью об исправлении
0 %
Медиана: публикация → KEV
676 дн.

Все записи

57 записей
  • CVE-2020-5722
    94Срочно

    The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request.

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 84 %

    grandstream · ucm6200 firmware23 мар. 2020 г.

  • CVE-2026-2329
    49В плане

    Grandstream GXP1600 VoIP Phones - Unauthenticated stack buffer overflow

    КритическаяCVSS 9,3Готовый эксплойтEPSS 41 %

    grandstream · gxp1610 firmware18 февр. 2026 г.

  • CVE-2019-10662
    48В плане

    Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the back

    ВысокаяCVSS 8,8Эксплойта нетEPSS 44 %

    grandstream · ucm6204 firmware30 мар. 2019 г.

  • CVE-2024-32937
    47В плане

    An os command injection vulnerability exists in the CWMP SelfDefinedTimeZone functionality of Grandstream GXP2135 1.0.9.129, 1.0.11.74 and 1

    КритическаяCVSS 9,8Эксплойта нетEPSS 26 %

    grandstream · gxp2135 firmware3 июл. 2024 г.

  • CVE-2019-10655
    44В плане

    Grandstream GAC2500 1.0.3.35, GXP2200 1.0.3.27, GVC3202 1.0.3.51, GXV3275 before 1.0.3.219 Beta, and GXV3240 before 1.0.3.219 Beta devices a

    КритическаяCVSS 9,8Готовый эксплойтEPSS 15 %

    grandstream · gac2500 firmware30 мар. 2019 г.

  • CVE-2019-10663
    43В плане

    Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to conduct SQL injection attacks via the sord parameter in a l

    ВысокаяCVSS 8,8Эксплойта нетEPSS 28 %

    grandstream · ucm6204 firmware30 мар. 2019 г.

  • CVE-2020-5757
    41В плане

    Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP.

    КритическаяCVSS 9,8Эксплойта нетEPSS 7 %

    grandstream · ucm6202 firmware17 июл. 2020 г.

  • CVE-2020-5723
    41В плане

    The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database.

    КритическаяCVSS 9,8Готовый эксплойтEPSS 6 %

    grandstream · ucm6202 firmware30 мар. 2020 г.

  • CVE-2022-2070
    41В плане

    Grandstream GSD3710 Stack-based Buffer Overflow

    КритическаяCVSS 9,8Proof of conceptEPSS 6 %

    grandstream · gds3710 firmware23 сент. 2022 г.

  • CVE-2022-2025
    41В плане

    Grandstream GSD3710 Stack-based Buffer Overflow

    КритическаяCVSS 9,8Proof of conceptEPSS 5 %

    grandstream · gds3710 firmware23 сент. 2022 г.

  • CVE-2013-3542
    41В плане

    Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P, GXV3651FHD, GXV3662HD, GXV3615WP_HD, GXV3500, and possibly ot

    КритическаяCVSS 10,0Эксплойта нетEPSS 3 %

    grandstream · gxv3501 firmware11 дек. 2019 г.

  • CVE-2020-5759
    40В плане

    Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via SSH.

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    grandstream · ucm6202 firmware17 июл. 2020 г.

  • CVE-2018-17565
    40В плане

    Shell Metacharacter Injection in the SSH configuration interface on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to execute ar

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    grandstream · gxp1610 firmware1 апр. 2019 г.

  • CVE-2020-25218
    40В плане

    Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allow Authentication Bypass in its administrative web interface.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    grandstream · grp2612 firmware29 мар. 2021 г.

  • CVE-2019-10661
    40В плане

    On Grandstream GXV3611IR_HD before 1.0.3.23 devices, the root account lacks a password.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    grandstream · gxv3611ir hd firmware30 мар. 2019 г.

  • CVE-2018-17564
    39Наблюдать

    A Malformed Input String to /cgi-bin/delete_CA on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to delete configuration paramet

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    grandstream · gxp1610 firmware1 апр. 2019 г.

  • CVE-2021-37748
    37Наблюдать

    Multiple buffer overflows in the limited configuration shell (/sbin/gs_config) on Grandstream HT801 devices before 1.0.29 allow remote authe

    ВысокаяCVSS 8,8Proof of conceptEPSS 7 %

    grandstream · ht801 firmware28 окт. 2021 г.

  • CVE-2020-5738
    37Наблюдать

    Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker uploads a s

    ВысокаяCVSS 8,8Эксплойта нетEPSS 5 %

    grandstream · gxp1610 firmware14 апр. 2020 г.

  • CVE-2020-5739
    37Наблюдать

    Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker adds an Ope

    ВысокаяCVSS 8,8Эксплойта нетEPSS 5 %

    grandstream · gxp1610 firmware14 апр. 2020 г.

  • CVE-2020-5758
    36Наблюдать

    Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %

    grandstream · ucm6202 firmware17 июл. 2020 г.

  • CVE-2019-10656
    36Наблюдать

    Grandstream GWN7000 before 1.0.6.32 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filen

    ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %

    grandstream · gwn7000 firmware30 мар. 2019 г.

  • CVE-2020-5763
    36Наблюдать

    Grandstream HT800 series firmware version 1.0.17.5 and below contain a backdoor in the SSH service.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %

    grandstream · ht801 firmware29 июл. 2020 г.

  • CVE-2019-10658
    36Наблюдать

    Grandstream GWN7610 before 1.0.8.18 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filen

    ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %

    grandstream · gwn7610 firmware30 мар. 2019 г.

  • CVE-2019-10660
    36Наблюдать

    Grandstream GXV3611IR_HD before 1.0.3.23 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the

    ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %

    grandstream · gxv3611ir hd firmware30 мар. 2019 г.

  • CVE-2019-10659
    36Наблюдать

    Grandstream GXV3370 before 1.0.1.41 and WP820 before 1.0.3.6 devices allow remote authenticated users to execute arbitrary code via shell me

    ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %

    grandstream · gxv3370 firmware30 мар. 2019 г.