Vulnerability index

Browse CVEs

54 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Gac2500 Firmware CRITICAL 9.8
CVE-2019-10655EPSS 15%

Grandstream GAC2500 1.0.3.35, GXP2200 1.0.3.27, GVC3202 1.0.3.51, GXV3275 before 1.0.3.219 Beta, and GXV3240 before 1.0.3.219 Beta devices allow unau…

Fix: 1.0.3.51 / 1.0.3.219+
Fix from $2,300 2019-03-30
Gxv3611ir Hd Firmware CRITICAL 9.8
CVE-2019-10661

On Grandstream GXV3611IR_HD before 1.0.3.23 devices, the root account lacks a password.

Fix: 1.0.3.23+
Fix from $2,300 2019-03-30
Gwn7000 Firmware HIGH 8.8
CVE-2019-10656

Grandstream GWN7000 before 1.0.6.32 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filename in a …

Fix: 1.0.6.32+
Fix from $1,950 2019-03-30
Gwn7610 Firmware HIGH 8.8
CVE-2019-10658

Grandstream GWN7610 before 1.0.8.18 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filename in a …

Fix: 1.0.8.18+
Fix from $1,950 2019-03-30
Gxv3370 Firmware HIGH 8.8
CVE-2019-10659

Grandstream GXV3370 before 1.0.1.41 and WP820 before 1.0.3.6 devices allow remote authenticated users to execute arbitrary code via shell metacharact…

Fix: 1.0.1.41 / 1.0.3.6+
Fix from $1,950 2019-03-30
Gxv3611ir Hd Firmware HIGH 8.8
CVE-2019-10660

Grandstream GXV3611IR_HD before 1.0.3.23 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the /goform/s…

Fix: 1.0.3.23+
Fix from $1,950 2019-03-30
Ucm6204 Firmware HIGH 8.8
CVE-2019-10662EPSS 44%

Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the backupUCMConf…

Fix: 1.0.19.20+
Fix from $1,950 2019-03-30
Ucm6204 Firmware HIGH 8.8
CVE-2019-10663EPSS 28%

Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to conduct SQL injection attacks via the sord parameter in a listCodebl…

Fix: 1.0.19.20+
Fix from $1,950 2019-03-30
Gwn7610 Firmware MEDIUM 6.5
CVE-2019-10657

Grandstream GWN7000 before 1.0.6.32 and GWN7610 before 1.0.8.18 devices allow remote authenticated users to discover passwords via a /ubus/uci.apply …

Fix: 1.0.6.32 / 1.0.8.18+
Fix from $1,600 2019-03-30
Ht802 Firmware HIGH 8.8
CVE-2017-16565

Cross-Site Request Forgery (CSRF) in /cgi-bin/login on Vonage (Grandstream) HT802 devices allows attackers to authenticate a user via the login scree…

No fix yet
Fix from $1,950 2017-11-06
Ht802 Firmware HIGH 8.0
CVE-2017-16563

Cross-Site Request Forgery (CSRF) in the Basic Settings screen on Vonage (Grandstream) HT802 devices allows attackers to modify settings, related to …

No fix yet
Fix from $1,950 2017-11-06
Ht802 Firmware MEDIUM 5.4
CVE-2017-16564

Stored Cross-site scripting (XSS) vulnerability in /cgi-bin/config2 on Vonage (Grandstream) HT802 devices allows remote authenticated users to inject…

No fix yet
Fix from $1,600 2017-11-06
Wave HIGH 8.1
CVE-2016-1518

The auto-provisioning mechanism in the Grandstream Wave app 1.0.1.26 and earlier for Android and Grandstream Video IP phones allows man-in-the-middle…

Fix: after 1.0.1.26
Fix from $1,950 2017-04-21
Wave HIGH 7.8
CVE-2016-1520

The Grandstream Wave app 1.0.1.26 and earlier for Android does not use HTTPS when retrieving update information, which might allow man-in-the-middle …

Fix: after 1.0.1.26
Fix from $1,950 2017-04-21
Wave MEDIUM 5.9
CVE-2016-1519

The com.softphone.common package in the Grandstream Wave app 1.0.1.26 and earlier for Android does not properly validate SSL certificates, which allo…

Fix: after 1.0.1.26
Fix from $1,600 2017-04-21
Gxv3611 Hd Firmware HIGH 7.5
CVE-2015-2866

SQL injection vulnerability on the Grandstream GXV3611_HD camera with firmware before 1.0.3.9 beta allows remote attackers to execute arbitrary SQL c…

Fix: after 1.0.3.6
Fix from $1,950 2015-07-08
Gxv Device Firmware MEDIUM 6.8
CVE-2013-3963

Cross-site request forgery (CSRF) vulnerability in goform/usermanage in Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P…

Fix: after 1.0.4.43
Fix from $1,600 2013-10-01
Ht488 HIGH 7.8
CVE-2007-5789

The Grandstream HT-488 0.1 allows remote attackers to cause a denial of service (device crash) via a flood of fragmented packets to port 5060.

Mitigation only
Fix from $1,950 2007-11-01
Ht488 HIGH 7.1
CVE-2007-5788

Buffer overflow in the SIP parser on the Grandstream HT-488 0.1 allows remote attackers to cause a denial of service (device crash) via a crafted SIP…

Mitigation only
Fix from $1,950 2007-11-01
Sip Phone HIGH 7.8
CVE-2007-4498EPSS 14%

The Grandstream SIP Phone GXV-3000 with firmware 1.0.1.7, Loader 1.0.0.6, and Boot 1.0.0.18 allows remote attackers to force silent call completion, …

No fix yet
Fix from $1,950 2007-08-23
Budgetone 200 HIGH 7.8
CVE-2007-1590

The Grandstream BudgeTone 200 IP phone, with program 1.1.1.14 and bootloader 1.1.1.5, allows remote attackers to cause a denial of service (device cr…

Mitigation only
Fix from $1,950 2007-03-21
Gxp 2000 HIGH 7.8
CVE-2006-5231

Grandstream GXP-2000 VoIP Desktop Phone, firmware version 1.1.0.5, allows remote attackers to cause a denial of service (hang or reboot) via a large …

Patch available
Fix from $1,950 2006-10-11
Budgetone 101 MEDIUM 5.0
CVE-2005-2581

Grandstream BudgeTone 101 and 102 running firmware 1.0.6.7 and possibly earlier versions, allows remote attackers to cause a denial of service (devic…

Fix: after 1.0.6.7
Fix from $1,600 2005-08-16
Bt 100 Firmware HIGH 7.5
CVE-2005-2182

Grandstream BudgeTone (BT) 100 Voice over IP (VoIP) phones do not properly check the Call-ID, branch, and tag values in a NOTIFY message to verify a …

Mitigation only
Fix from $1,950 2005-07-11