Vulnerability index

Browse CVEs

17 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Gxp2135 Firmware CRITICAL 9.8
CVE-2024-32937EPSS 26%

An os command injection vulnerability exists in the CWMP SelfDefinedTimeZone functionality of Grandstream GXP2135 1.0.9.129, 1.0.11.74 and 1.0.11.79.…

No fix yet
Fix from $2,300 2024-07-03
Gds3710 Firmware CRITICAL 9.8
CVE-2022-2025

an attacker with knowledge of user/pass of Grandstream GSD3710 in its 1.0.11.13 version, could overflow the stack since it doesn't check the param le…

Mitigation only
Fix from $2,300 2022-09-23
Gds3710 Firmware CRITICAL 9.8
CVE-2022-2070

In Grandstream GSD3710 in its 1.0.11.13 version, it's possible to overflow the stack since it doesn't check the param length before using the sscanf …

Mitigation only
Fix from $2,300 2022-09-23
Grp2612 Firmware CRITICAL 9.8
CVE-2020-25218

Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allow Authentication Bypass in its administrative web interface.

Mitigation only
Fix from $2,300 2021-03-29
Grp2612 Firmware HIGH 7.2
CVE-2020-25217

Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allows Command Injection as root in its administrative web interface.

Mitigation only
Fix from $1,950 2021-03-29
Gxv3501 Firmware CRITICAL 10.0
CVE-2013-3542

Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P, GXV3651FHD, GXV3662HD, GXV3615WP_HD, GXV3500, and possibly other camer…

Mitigation only
Fix from $2,300 2019-12-11
Gxp1610 Firmware CRITICAL 9.8
CVE-2018-17564

A Malformed Input String to /cgi-bin/delete_CA on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to delete configuration parameters and g…

Mitigation only
Fix from $2,300 2019-04-01
Gxp1610 Firmware CRITICAL 9.8
CVE-2018-17565

Shell Metacharacter Injection in the SSH configuration interface on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to execute arbitrary s…

Mitigation only
Fix from $2,300 2019-04-01
Gxp1610 Firmware MEDIUM 5.3
CVE-2018-17563

A Malformed Input String to /cgi-bin/api-get_line_status on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to dump the device's configura…

Mitigation only
Fix from $1,600 2019-04-01
Ht802 Firmware HIGH 8.8
CVE-2017-16565

Cross-Site Request Forgery (CSRF) in /cgi-bin/login on Vonage (Grandstream) HT802 devices allows attackers to authenticate a user via the login scree…

No fix yet
Fix from $1,950 2017-11-06
Ht802 Firmware HIGH 8.0
CVE-2017-16563

Cross-Site Request Forgery (CSRF) in the Basic Settings screen on Vonage (Grandstream) HT802 devices allows attackers to modify settings, related to …

No fix yet
Fix from $1,950 2017-11-06
Ht802 Firmware MEDIUM 5.4
CVE-2017-16564

Stored Cross-site scripting (XSS) vulnerability in /cgi-bin/config2 on Vonage (Grandstream) HT802 devices allows remote authenticated users to inject…

No fix yet
Fix from $1,600 2017-11-06
Ht488 HIGH 7.8
CVE-2007-5789

The Grandstream HT-488 0.1 allows remote attackers to cause a denial of service (device crash) via a flood of fragmented packets to port 5060.

Mitigation only
Fix from $1,950 2007-11-01
Ht488 HIGH 7.1
CVE-2007-5788

Buffer overflow in the SIP parser on the Grandstream HT-488 0.1 allows remote attackers to cause a denial of service (device crash) via a crafted SIP…

Mitigation only
Fix from $1,950 2007-11-01
Sip Phone HIGH 7.8
CVE-2007-4498EPSS 14%

The Grandstream SIP Phone GXV-3000 with firmware 1.0.1.7, Loader 1.0.0.6, and Boot 1.0.0.18 allows remote attackers to force silent call completion, …

No fix yet
Fix from $1,950 2007-08-23
Budgetone 200 HIGH 7.8
CVE-2007-1590

The Grandstream BudgeTone 200 IP phone, with program 1.1.1.14 and bootloader 1.1.1.5, allows remote attackers to cause a denial of service (device cr…

Mitigation only
Fix from $1,950 2007-03-21
Bt 100 Firmware HIGH 7.5
CVE-2005-2182

Grandstream BudgeTone (BT) 100 Voice over IP (VoIP) phones do not properly check the Call-ID, branch, and tag values in a NOTIFY message to verify a …

Mitigation only
Fix from $1,950 2005-07-11