Grandstream kayıtları
grandstream üreticisine ait 57 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %1,8
- Silahlaştırılmış
- 5 · %8,8
- Pre-auth RCE
- 7
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- 676 gün
Tekrar eden sınıflar
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')13
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')6
- CWE-121 Stack-based Buffer Overflow3
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-489 Active Debug Code2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
57 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
94Hemen | CVE-2020-5722Silahlaştırılmış | The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request.grandstream · ucm6200 firmware · CWE-89 | Kritik9,8 | KEV | %84,4 | 23 Mar 2020 |
49Planlayın | CVE-2026-2329Silahlaştırılmış | Grandstream GXP1600 VoIP Phones - Unauthenticated stack buffer overflowgrandstream · gxp1610 firmware · CWE-121 | Kritik9,3 | — | %40,6 | 18 Şub 2026 |
48Planlayın | CVE-2019-10662İstismar yok | Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the backgrandstream · ucm6204 firmware · CWE-78 | Yüksek8,8 | — | %43,9 | 30 Mar 2019 |
47Planlayın | CVE-2024-32937İstismar yok | An os command injection vulnerability exists in the CWMP SelfDefinedTimeZone functionality of Grandstream GXP2135 1.0.9.129, 1.0.11.74 and 1grandstream · gxp2135 firmware · CWE-78 | Kritik9,8 | — | %26,3 | 3 Tem 2024 |
44Planlayın | CVE-2019-10655Silahlaştırılmış | Grandstream GAC2500 1.0.3.35, GXP2200 1.0.3.27, GVC3202 1.0.3.51, GXV3275 before 1.0.3.219 Beta, and GXV3240 before 1.0.3.219 Beta devices agrandstream · gac2500 firmware · CWE-78 | Kritik9,8 | — | %15,5 | 30 Mar 2019 |
43Planlayın | CVE-2019-10663İstismar yok | Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to conduct SQL injection attacks via the sord parameter in a lgrandstream · ucm6204 firmware · CWE-89 | Yüksek8,8 | — | %27,9 | 30 Mar 2019 |
41Planlayın | CVE-2020-5757İstismar yok | Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP.grandstream · ucm6202 firmware · CWE-78 | Kritik9,8 | — | %6,9 | 17 Tem 2020 |
41Planlayın | CVE-2020-5723Silahlaştırılmış | The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database.grandstream · ucm6202 firmware · CWE-312 | Kritik9,8 | — | %5,9 | 30 Mar 2020 |
41Planlayın | CVE-2022-2070Kavram kanıtı | Grandstream GSD3710 Stack-based Buffer Overflowgrandstream · gds3710 firmware · CWE-121 | Kritik9,8 | — | %5,7 | 23 Eyl 2022 |
41Planlayın | CVE-2022-2025Kavram kanıtı | Grandstream GSD3710 Stack-based Buffer Overflowgrandstream · gds3710 firmware · CWE-121 | Kritik9,8 | — | %5,3 | 23 Eyl 2022 |
41Planlayın | CVE-2013-3542İstismar yok | Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P, GXV3651FHD, GXV3662HD, GXV3615WP_HD, GXV3500, and possibly otgrandstream · gxv3501 firmware · CWE-798 | Kritik10,0 | — | %2,6 | 11 Ara 2019 |
40Planlayın | CVE-2020-5759İstismar yok | Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via SSH.grandstream · ucm6202 firmware · CWE-78 | Kritik9,8 | — | %3,2 | 17 Tem 2020 |
40Planlayın | CVE-2018-17565İstismar yok | Shell Metacharacter Injection in the SSH configuration interface on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to execute argrandstream · gxp1610 firmware · CWE-78 | Kritik9,8 | — | %1,9 | 1 Nis 2019 |
40Planlayın | CVE-2020-25218İstismar yok | Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allow Authentication Bypass in its administrative web interface.grandstream · grp2612 firmware · CWE-306 | Kritik9,8 | — | %1,8 | 29 Mar 2021 |
40Planlayın | CVE-2019-10661İstismar yok | On Grandstream GXV3611IR_HD before 1.0.3.23 devices, the root account lacks a password.grandstream · gxv3611ir hd firmware · CWE-287 | Kritik9,8 | — | %1,8 | 30 Mar 2019 |
39İzleyin | CVE-2018-17564İstismar yok | A Malformed Input String to /cgi-bin/delete_CA on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to delete configuration parametgrandstream · gxp1610 firmware | Kritik9,8 | — | %1,6 | 1 Nis 2019 |
37İzleyin | CVE-2021-37748Kavram kanıtı | Multiple buffer overflows in the limited configuration shell (/sbin/gs_config) on Grandstream HT801 devices before 1.0.29 allow remote authegrandstream · ht801 firmware · CWE-787 | Yüksek8,8 | — | %7,4 | 28 Eki 2021 |
37İzleyin | CVE-2020-5738İstismar yok | Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker uploads a sgrandstream · gxp1610 firmware · CWE-59 | Yüksek8,8 | — | %5,4 | 14 Nis 2020 |
37İzleyin | CVE-2020-5739İstismar yok | Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker adds an Opegrandstream · gxp1610 firmware · CWE-94 | Yüksek8,8 | — | %5,3 | 14 Nis 2020 |
36İzleyin | CVE-2020-5758İstismar yok | Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP.grandstream · ucm6202 firmware · CWE-78 | Yüksek8,8 | — | %4,4 | 17 Tem 2020 |
36İzleyin | CVE-2019-10656İstismar yok | Grandstream GWN7000 before 1.0.6.32 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filengrandstream · gwn7000 firmware · CWE-78 | Yüksek8,8 | — | %3,9 | 30 Mar 2019 |
36İzleyin | CVE-2020-5763İstismar yok | Grandstream HT800 series firmware version 1.0.17.5 and below contain a backdoor in the SSH service.grandstream · ht801 firmware · CWE-489 | Yüksek8,8 | — | %2,7 | 29 Tem 2020 |
36İzleyin | CVE-2019-10658İstismar yok | Grandstream GWN7610 before 1.0.8.18 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filengrandstream · gwn7610 firmware · CWE-78 | Yüksek8,8 | — | %2,6 | 30 Mar 2019 |
36İzleyin | CVE-2019-10660İstismar yok | Grandstream GXV3611IR_HD before 1.0.3.23 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the grandstream · gxv3611ir hd firmware · CWE-78 | Yüksek8,8 | — | %2,6 | 30 Mar 2019 |
36İzleyin | CVE-2019-10659İstismar yok | Grandstream GXV3370 before 1.0.1.41 and WP820 before 1.0.3.6 devices allow remote authenticated users to execute arbitrary code via shell megrandstream · gxv3370 firmware · CWE-78 | Yüksek8,8 | — | %2,6 | 30 Mar 2019 |
- CVE-2020-572294Hemen
The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %84grandstream · ucm6200 firmware23 Mar 2020
- CVE-2026-232949Planlayın
Grandstream GXP1600 VoIP Phones - Unauthenticated stack buffer overflow
KritikCVSS 9,3SilahlaştırılmışEPSS %41grandstream · gxp1610 firmware18 Şub 2026
- CVE-2019-1066248Planlayın
Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the back
YüksekCVSS 8,8İstismar yokEPSS %44grandstream · ucm6204 firmware30 Mar 2019
- CVE-2024-3293747Planlayın
An os command injection vulnerability exists in the CWMP SelfDefinedTimeZone functionality of Grandstream GXP2135 1.0.9.129, 1.0.11.74 and 1
KritikCVSS 9,8İstismar yokEPSS %26grandstream · gxp2135 firmware3 Tem 2024
- CVE-2019-1065544Planlayın
Grandstream GAC2500 1.0.3.35, GXP2200 1.0.3.27, GVC3202 1.0.3.51, GXV3275 before 1.0.3.219 Beta, and GXV3240 before 1.0.3.219 Beta devices a
KritikCVSS 9,8SilahlaştırılmışEPSS %15grandstream · gac2500 firmware30 Mar 2019
- CVE-2019-1066343Planlayın
Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to conduct SQL injection attacks via the sord parameter in a l
YüksekCVSS 8,8İstismar yokEPSS %28grandstream · ucm6204 firmware30 Mar 2019
- CVE-2020-575741Planlayın
Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP.
KritikCVSS 9,8İstismar yokEPSS %7grandstream · ucm6202 firmware17 Tem 2020
- CVE-2020-572341Planlayın
The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database.
KritikCVSS 9,8SilahlaştırılmışEPSS %6grandstream · ucm6202 firmware30 Mar 2020
- CVE-2022-207041Planlayın
Grandstream GSD3710 Stack-based Buffer Overflow
KritikCVSS 9,8Kavram kanıtıEPSS %6grandstream · gds3710 firmware23 Eyl 2022
- CVE-2022-202541Planlayın
Grandstream GSD3710 Stack-based Buffer Overflow
KritikCVSS 9,8Kavram kanıtıEPSS %5grandstream · gds3710 firmware23 Eyl 2022
- CVE-2013-354241Planlayın
Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P, GXV3651FHD, GXV3662HD, GXV3615WP_HD, GXV3500, and possibly ot
KritikCVSS 10,0İstismar yokEPSS %3grandstream · gxv3501 firmware11 Ara 2019
- CVE-2020-575940Planlayın
Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via SSH.
KritikCVSS 9,8İstismar yokEPSS %3grandstream · ucm6202 firmware17 Tem 2020
- CVE-2018-1756540Planlayın
Shell Metacharacter Injection in the SSH configuration interface on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to execute ar
KritikCVSS 9,8İstismar yokEPSS %2grandstream · gxp1610 firmware1 Nis 2019
- CVE-2020-2521840Planlayın
Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allow Authentication Bypass in its administrative web interface.
KritikCVSS 9,8İstismar yokEPSS %2grandstream · grp2612 firmware29 Mar 2021
- CVE-2019-1066140Planlayın
On Grandstream GXV3611IR_HD before 1.0.3.23 devices, the root account lacks a password.
KritikCVSS 9,8İstismar yokEPSS %2grandstream · gxv3611ir hd firmware30 Mar 2019
- CVE-2018-1756439İzleyin
A Malformed Input String to /cgi-bin/delete_CA on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to delete configuration paramet
KritikCVSS 9,8İstismar yokEPSS %2grandstream · gxp1610 firmware1 Nis 2019
- CVE-2021-3774837İzleyin
Multiple buffer overflows in the limited configuration shell (/sbin/gs_config) on Grandstream HT801 devices before 1.0.29 allow remote authe
YüksekCVSS 8,8Kavram kanıtıEPSS %7grandstream · ht801 firmware28 Eki 2021
- CVE-2020-573837İzleyin
Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker uploads a s
YüksekCVSS 8,8İstismar yokEPSS %5grandstream · gxp1610 firmware14 Nis 2020
- CVE-2020-573937İzleyin
Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker adds an Ope
YüksekCVSS 8,8İstismar yokEPSS %5grandstream · gxp1610 firmware14 Nis 2020
- CVE-2020-575836İzleyin
Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP.
YüksekCVSS 8,8İstismar yokEPSS %4grandstream · ucm6202 firmware17 Tem 2020
- CVE-2019-1065636İzleyin
Grandstream GWN7000 before 1.0.6.32 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filen
YüksekCVSS 8,8İstismar yokEPSS %4grandstream · gwn7000 firmware30 Mar 2019
- CVE-2020-576336İzleyin
Grandstream HT800 series firmware version 1.0.17.5 and below contain a backdoor in the SSH service.
YüksekCVSS 8,8İstismar yokEPSS %3grandstream · ht801 firmware29 Tem 2020
- CVE-2019-1065836İzleyin
Grandstream GWN7610 before 1.0.8.18 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filen
YüksekCVSS 8,8İstismar yokEPSS %3grandstream · gwn7610 firmware30 Mar 2019
- CVE-2019-1066036İzleyin
Grandstream GXV3611IR_HD before 1.0.3.23 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the
YüksekCVSS 8,8İstismar yokEPSS %3grandstream · gxv3611ir hd firmware30 Mar 2019
- CVE-2019-1065936İzleyin
Grandstream GXV3370 before 1.0.1.41 and WP820 before 1.0.3.6 devices allow remote authenticated users to execute arbitrary code via shell me
YüksekCVSS 8,8İstismar yokEPSS %3grandstream · gxv3370 firmware30 Mar 2019