İçeriğe atla
Noroxi

Grandstream kayıtları

grandstream üreticisine ait 57 yayımlanmış kayıt.

Tüm kayıtlar

57 kayıt
  • The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %84

    grandstream · ucm6200 firmware23 Mar 2020

  • CVE-2026-2329
    49Planlayın

    Grandstream GXP1600 VoIP Phones - Unauthenticated stack buffer overflow

    KritikCVSS 9,3SilahlaştırılmışEPSS %41

    grandstream · gxp1610 firmware18 Şub 2026

  • CVE-2019-10662
    48Planlayın

    Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the back

    YüksekCVSS 8,8İstismar yokEPSS %44

    grandstream · ucm6204 firmware30 Mar 2019

  • CVE-2024-32937
    47Planlayın

    An os command injection vulnerability exists in the CWMP SelfDefinedTimeZone functionality of Grandstream GXP2135 1.0.9.129, 1.0.11.74 and 1

    KritikCVSS 9,8İstismar yokEPSS %26

    grandstream · gxp2135 firmware3 Tem 2024

  • CVE-2019-10655
    44Planlayın

    Grandstream GAC2500 1.0.3.35, GXP2200 1.0.3.27, GVC3202 1.0.3.51, GXV3275 before 1.0.3.219 Beta, and GXV3240 before 1.0.3.219 Beta devices a

    KritikCVSS 9,8SilahlaştırılmışEPSS %15

    grandstream · gac2500 firmware30 Mar 2019

  • CVE-2019-10663
    43Planlayın

    Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to conduct SQL injection attacks via the sord parameter in a l

    YüksekCVSS 8,8İstismar yokEPSS %28

    grandstream · ucm6204 firmware30 Mar 2019

  • CVE-2020-5757
    41Planlayın

    Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP.

    KritikCVSS 9,8İstismar yokEPSS %7

    grandstream · ucm6202 firmware17 Tem 2020

  • CVE-2020-5723
    41Planlayın

    The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database.

    KritikCVSS 9,8SilahlaştırılmışEPSS %6

    grandstream · ucm6202 firmware30 Mar 2020

  • CVE-2022-2070
    41Planlayın

    Grandstream GSD3710 Stack-based Buffer Overflow

    KritikCVSS 9,8Kavram kanıtıEPSS %6

    grandstream · gds3710 firmware23 Eyl 2022

  • CVE-2022-2025
    41Planlayın

    Grandstream GSD3710 Stack-based Buffer Overflow

    KritikCVSS 9,8Kavram kanıtıEPSS %5

    grandstream · gds3710 firmware23 Eyl 2022

  • CVE-2013-3542
    41Planlayın

    Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P, GXV3651FHD, GXV3662HD, GXV3615WP_HD, GXV3500, and possibly ot

    KritikCVSS 10,0İstismar yokEPSS %3

    grandstream · gxv3501 firmware11 Ara 2019

  • CVE-2020-5759
    40Planlayın

    Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via SSH.

    KritikCVSS 9,8İstismar yokEPSS %3

    grandstream · ucm6202 firmware17 Tem 2020

  • CVE-2018-17565
    40Planlayın

    Shell Metacharacter Injection in the SSH configuration interface on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to execute ar

    KritikCVSS 9,8İstismar yokEPSS %2

    grandstream · gxp1610 firmware1 Nis 2019

  • CVE-2020-25218
    40Planlayın

    Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allow Authentication Bypass in its administrative web interface.

    KritikCVSS 9,8İstismar yokEPSS %2

    grandstream · grp2612 firmware29 Mar 2021

  • CVE-2019-10661
    40Planlayın

    On Grandstream GXV3611IR_HD before 1.0.3.23 devices, the root account lacks a password.

    KritikCVSS 9,8İstismar yokEPSS %2

    grandstream · gxv3611ir hd firmware30 Mar 2019

  • CVE-2018-17564
    39İzleyin

    A Malformed Input String to /cgi-bin/delete_CA on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to delete configuration paramet

    KritikCVSS 9,8İstismar yokEPSS %2

    grandstream · gxp1610 firmware1 Nis 2019

  • CVE-2021-37748
    37İzleyin

    Multiple buffer overflows in the limited configuration shell (/sbin/gs_config) on Grandstream HT801 devices before 1.0.29 allow remote authe

    YüksekCVSS 8,8Kavram kanıtıEPSS %7

    grandstream · ht801 firmware28 Eki 2021

  • CVE-2020-5738
    37İzleyin

    Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker uploads a s

    YüksekCVSS 8,8İstismar yokEPSS %5

    grandstream · gxp1610 firmware14 Nis 2020

  • CVE-2020-5739
    37İzleyin

    Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker adds an Ope

    YüksekCVSS 8,8İstismar yokEPSS %5

    grandstream · gxp1610 firmware14 Nis 2020

  • CVE-2020-5758
    36İzleyin

    Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP.

    YüksekCVSS 8,8İstismar yokEPSS %4

    grandstream · ucm6202 firmware17 Tem 2020

  • CVE-2019-10656
    36İzleyin

    Grandstream GWN7000 before 1.0.6.32 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filen

    YüksekCVSS 8,8İstismar yokEPSS %4

    grandstream · gwn7000 firmware30 Mar 2019

  • CVE-2020-5763
    36İzleyin

    Grandstream HT800 series firmware version 1.0.17.5 and below contain a backdoor in the SSH service.

    YüksekCVSS 8,8İstismar yokEPSS %3

    grandstream · ht801 firmware29 Tem 2020

  • CVE-2019-10658
    36İzleyin

    Grandstream GWN7610 before 1.0.8.18 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filen

    YüksekCVSS 8,8İstismar yokEPSS %3

    grandstream · gwn7610 firmware30 Mar 2019

  • CVE-2019-10660
    36İzleyin

    Grandstream GXV3611IR_HD before 1.0.3.23 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the

    YüksekCVSS 8,8İstismar yokEPSS %3

    grandstream · gxv3611ir hd firmware30 Mar 2019

  • CVE-2019-10659
    36İzleyin

    Grandstream GXV3370 before 1.0.1.41 and WP820 before 1.0.3.6 devices allow remote authenticated users to execute arbitrary code via shell me

    YüksekCVSS 8,8İstismar yokEPSS %3

    grandstream · gxv3370 firmware30 Mar 2019