VYPR

HT801

by Grandstream

CVEs (2)

  • CVE-2021-37748HigOct 28, 2021
    risk 0.58cvss 8.8epss 0.07

    Multiple buffer overflows in the limited configuration shell (/sbin/gs_config) on Grandstream HT801 devices before 1.0.29 allow remote authenticated users to execute arbitrary code as root via a crafted manage_if setting, thus bypassing the intended restrictions of this shell…

  • CVE-2021-37915HigOct 28, 2021
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered on the Grandstream HT801 Analog Telephone Adaptor before 1.0.29.8. From the limited configuration shell, it is possible to set the malicious gdb_debug_server variable. As a result, after a reboot, the device downloads and executes malicious scripts from…