Critical severity9.8NVD Advisory· Published Mar 29, 2021· Updated Jun 17, 2026
CVE-2020-25218
CVE-2020-25218
Description
Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allow Authentication Bypass in its administrative web interface.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9= 1.0.3.6+ 1 more
- (no CPE)range: = 1.0.3.6
- (no CPE)
- cpe:2.3:o:grandstream:grp2612_firmware:1.0.3.6:*:*:*:*:*:*:*
- cpe:2.3:o:grandstream:grp2612p_firmware:1.0.3.6:*:*:*:*:*:*:*
- cpe:2.3:o:grandstream:grp2612w_firmware:1.0.3.6:*:*:*:*:*:*:*
- cpe:2.3:o:grandstream:grp2613_firmware:1.0.3.6:*:*:*:*:*:*:*
- cpe:2.3:o:grandstream:grp2614_firmware:1.0.3.6:*:*:*:*:*:*:*
- cpe:2.3:o:grandstream:grp2615_firmware:1.0.3.6:*:*:*:*:*:*:*
- cpe:2.3:o:grandstream:grp2616_firmware:1.0.3.6:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2- cwe.mitre.org/data/definitions/306.htmlnvdThird Party Advisory
- github.com/fireeye/Vulnerability-Disclosures/blob/master/FEYE-2021-0002/FEYE-2021-0002.mdnvdThird Party Advisory
News mentions
0No linked articles in our index yet.