VYPR
Vendor

Grandstream

Products
103
CVEs
59
Across products
139
Status
Private

Products

103
View all 103 products →

Recent CVEs

59
View all 59 CVEs →
  • CVE-2020-5722CriKEVMar 23, 2020
    risk 0.85cvss 9.8epss 0.84

    The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. An attacker can use this vulnerability to execute shell commands as root on versions before 1.0.19.20 or inject HTML in password recovery…

  • CVE-2026-2329CriFeb 18, 2026
    risk 0.70cvss 9.8epss 0.40

    An unauthenticated stack-based buffer overflow vulnerability exists in the HTTP API endpoint /cgi-bin/api.values.get. A remote attacker can leverage this vulnerability to achieve unauthenticated remote code execution (RCE) with root privileges on a target device. The…

  • CVE-2019-10655CriMar 30, 2019
    risk 0.68cvss 9.8epss 0.15

    Grandstream GAC2500 1.0.3.35, GXP2200 1.0.3.27, GVC3202 1.0.3.51, GXV3275 before 1.0.3.219 Beta, and GXV3240 before 1.0.3.219 Beta devices allow unauthenticated remote code execution via shell metacharacters in a /manager?action=getlogcat priority field, in conjunction with a…

  • CVE-2022-2070CriSep 23, 2022
    risk 0.67cvss 9.8epss 0.05

    In Grandstream GSD3710 in its 1.0.11.13 version, it's possible to overflow the stack since it doesn't check the param length before using the sscanf instruction. Because of that, an attacker could create a socket and connect with a remote IP:port by opening a shell and getting…

  • CVE-2022-2025CriSep 23, 2022
    risk 0.67cvss 9.8epss 0.04

    an attacker with knowledge of user/pass of Grandstream GSD3710 in its 1.0.11.13 version, could overflow the stack since it doesn't check the param length before use the strcopy instruction. The explotation of this vulnerability may lead an attacker to execute a shell with full…

  • CVE-2020-5723CriMar 30, 2020
    risk 0.67cvss 9.8epss 0.06

    The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database. This could allow an attacker to retrieve all passwords and possibly gain elevated privileges.

  • CVE-2013-3542CriDec 11, 2019
    risk 0.65cvss 10.0epss 0.03

    Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P, GXV3651FHD, GXV3662HD, GXV3615WP_HD, GXV3500, and possibly other camera models with firmware 1.0.4.11, have a hardcoded account "!#/" with the same password, which makes it easier for remote attackers…

  • CVE-2020-25218CriMar 29, 2021
    risk 0.64cvss 9.8epss 0.02

    Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allow Authentication Bypass in its administrative web interface.

  • CVE-2020-5759CriJul 17, 2020
    risk 0.64cvss 9.8epss 0.03

    Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via SSH. An authenticated remote attacker can execute commands as the root user by issuing a specially crafted "unset" command.

  • CVE-2020-5757CriJul 17, 2020
    risk 0.64cvss 9.8epss 0.07

    Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authenticated remote attacker can bypass command injection mitigations and execute commands as the root user by sending a crafted HTTP POST to the UCM's "New" HTTPS…

  • CVE-2018-17565CriApr 1, 2019
    risk 0.64cvss 9.8epss 0.02

    Shell Metacharacter Injection in the SSH configuration interface on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to execute arbitrary system commands and gain a root shell.

  • CVE-2018-17564CriApr 1, 2019
    risk 0.64cvss 9.8epss 0.02

    A Malformed Input String to /cgi-bin/delete_CA on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to delete configuration parameters and gain admin access to the device.

  • CVE-2019-10661CriMar 30, 2019
    risk 0.64cvss 9.8epss 0.02

    On Grandstream GXV3611IR_HD before 1.0.3.23 devices, the root account lacks a password.

  • CVE-2019-10662HigMar 30, 2019
    risk 0.61cvss 8.8epss 0.44

    Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the backupUCMConfig file-backup parameter to the /cgi? URI.

  • CVE-2019-10663HigMar 30, 2019
    risk 0.59cvss 8.8epss 0.28

    Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to conduct SQL injection attacks via the sord parameter in a listCodeblueGroup API call to the /cgi? URI.

  • CVE-2021-37748HigOct 28, 2021
    risk 0.58cvss 8.8epss 0.07

    Multiple buffer overflows in the limited configuration shell (/sbin/gs_config) on Grandstream HT801 devices before 1.0.29 allow remote authenticated users to execute arbitrary code as root via a crafted manage_if setting, thus bypassing the intended restrictions of this shell…

  • CVE-2020-5758HigJul 17, 2020
    risk 0.58cvss 8.8epss 0.04

    Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authenticated remote attacker can execute commands as the root user by sending a crafted HTTP GET to the UCM's "Old" HTTPS API.

  • CVE-2020-5739HigApr 14, 2020
    risk 0.58cvss 8.8epss 0.05

    Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker adds an OpenVPN up script to the phone's VPN settings via the "Additional Settings" field in the web interface. When the VPN's connection is…

  • CVE-2020-5738HigApr 14, 2020
    risk 0.58cvss 8.8epss 0.05

    Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker uploads a specially crafted tar file to the HTTP /cgi-bin/upload_vpntar interface.

  • CVE-2019-10656HigMar 30, 2019
    risk 0.58cvss 8.8epss 0.04

    Grandstream GWN7000 before 1.0.6.32 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filename in a /ubus/uci.apply update_nds_webroot_from_tmp API call.