Vulnerabilities (CVE)

Filtered by vendor Grandstream Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-10657 1 Grandstream 4 Gwn7000, Gwn7000 Firmware, Gwn7610 and 1 more 2020-08-24 4.0 MEDIUM 6.5 MEDIUM
Grandstream GWN7000 before 1.0.6.32 and GWN7610 before 1.0.8.18 devices allow remote authenticated users to discover passwords via a /ubus/uci.apply config request.
CVE-2020-5725 1 Grandstream 6 Ucm6202, Ucm6202 Firmware, Ucm6204 and 3 more 2020-03-31 4.3 MEDIUM 5.9 MEDIUM
The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpoint. A remote unauthenticated attacker can invoke the login action with a crafted username and, through the use of timing attacks, can discover user passwords.
CVE-2018-17563 1 Grandstream 12 Gxp1610, Gxp1610 Firmware, Gxp1615 and 9 more 2019-10-03 5.0 MEDIUM 5.3 MEDIUM
A Malformed Input String to /cgi-bin/api-get_line_status on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to dump the device's configuration in cleartext.
CVE-2016-1519 1 Grandstream 1 Wave 2018-10-09 4.3 MEDIUM 5.9 MEDIUM
The com.softphone.common package in the Grandstream Wave app 1.0.1.26 and earlier for Android does not properly validate SSL certificates, which allows man-in-the-middle attackers to spoof the Grandstream provisioning server via a crafted certificate.
CVE-2017-16564 1 Grandstream 2 Ht802, Ht802 Firmware 2017-11-27 3.5 LOW 5.4 MEDIUM
Stored Cross-site scripting (XSS) vulnerability in /cgi-bin/config2 on Vonage (Grandstream) HT802 devices allows remote authenticated users to inject arbitrary web script or HTML via the DHCP vendor class ID field (P148).