Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2026-2329EPSS 40%
An unauthenticated stack-based buffer overflow vulnerability exists in the HTTP API endpoint /cgi-bin/api.values.get. A remote attacker can leverage …
Gxp1610 Firmware
1.0.7.81+
HIGH 7.6
CVE-2025-28170
Grandstream Networks GXP1628 <=1.0.4.130 is vulnerable to Incorrect Access Control. The device is configured with directory listing enabled, allowing…
Gxp1628 Firmware
after 1.0.4.130
MEDIUM 6.5
CVE-2025-28171
An issue in Grandstream UCM6510 v.1.0.20.52 and before allows a remote attacker to obtain sensitive information via the Login function at /cgi and /w…
Ucm6510 Firmware
after 1.0.20.52
MEDIUM 6.5
CVE-2025-28172
Grandstream Networks UCM6510 v1.0.20.52 and before is vulnerable to Improper Restriction of Excessive Authentication Attempts. An attacker can perfor…
Ucm6510 Firmware
after 1.0.20.52
CRITICAL 9.8
CVE-2024-32937EPSS 26%
An os command injection vulnerability exists in the CWMP SelfDefinedTimeZone functionality of Grandstream GXP2135 1.0.9.129, 1.0.11.74 and 1.0.11.79.…
Gxp2135 Firmware
No fix yet
CRITICAL 9.8
CVE-2022-2025
an attacker with knowledge of user/pass of Grandstream GSD3710 in its 1.0.11.13 version, could overflow the stack since it doesn't check the param le…
Gds3710 Firmware
Mitigation only
CRITICAL 9.8
CVE-2022-2070
In Grandstream GSD3710 in its 1.0.11.13 version, it's possible to overflow the stack since it doesn't check the param length before using the sscanf …
Gds3710 Firmware
Mitigation only
HIGH 8.8
CVE-2021-37748EPSS 7%
Multiple buffer overflows in the limited configuration shell (/sbin/gs_config) on Grandstream HT801 devices before 1.0.29 allow remote authenticated …
Ht801 Firmware
1.0.29+
HIGH 8.8
CVE-2021-37915
An issue was discovered on the Grandstream HT801 Analog Telephone Adaptor before 1.0.29.8. From the limited configuration shell, it is possible to se…
Ht801 Firmware
1.0.29.8+
CRITICAL 9.8
CVE-2020-25218
Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allow Authentication Bypass in its administrative web interface.
Grp2612 Firmware
Mitigation only
HIGH 7.2
CVE-2020-25217
Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allows Command Injection as root in its administrative web interface.
Grp2612 Firmware
Mitigation only
HIGH 8.8
CVE-2020-5763
Grandstream HT800 series firmware version 1.0.17.5 and below contain a backdoor in the SSH service. An authenticated remote attacker can obtain a roo…
Ht801 Firmware
after 1.0.17.5
HIGH 7.5
CVE-2020-5761
Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to CPU exhaustion due to an infinite loop in the TR-069 service. Unauthent…
Ht801 Firmware
after 1.0.17.5
HIGH 7.5
CVE-2020-5762
Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to a denial of service attack against the TR-069 service. An unauthenticat…
Ht801 Firmware
after 1.0.17.5
HIGH 7.8
CVE-2020-5760EPSS 5%
Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to an OS command injection vulnerability. Unauthenticated remote attackers…
Ht801 Firmware
after 1.0.17.5
CRITICAL 9.8
CVE-2020-5757EPSS 7%
Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authenticated remote attacker can …
Ucm6202 Firmware
after 1.0.20.23
CRITICAL 9.8
CVE-2020-5759
Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via SSH. An authenticated remote attacker can e…
Ucm6202 Firmware
after 1.0.20.23
HIGH 8.8
CVE-2020-5756
Grandstream GWN7000 firmware version 1.0.9.4 and below allows authenticated remote users to modify the system's crontab via undocumented API. An atta…
Gwn7000 Firmware
after 1.0.9.4
HIGH 8.8
CVE-2020-5758
Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authenticated remote attacker can …
Ucm6202 Firmware
after 1.0.20.23
HIGH 8.8
CVE-2020-5739EPSS 5%
Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker adds an OpenVPN up s…
Gxp1610 Firmware
after 1.0.4.152
HIGH 8.8
CVE-2020-5738EPSS 5%
Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker uploads a specially …
Gxp1610 Firmware
after 1.0.4.152
HIGH 7.5
CVE-2020-5724EPSS 12%
The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpoint. A remote unauthenticated…
Ucm6202 Firmware
1.0.20.22+
HIGH 7.5
CVE-2020-5726
The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the CTI server on port 8888. A remote unauthenticated attacker …
Ucm6202 Firmware
1.0.20.22+
MEDIUM 5.9
CVE-2020-5725
The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpoint. A remote unauthenticated…
Ucm6202 Firmware
1.0.20.22+
CRITICAL 9.8
CVE-2020-5723EPSS 6%
The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database. This could allow an attacker to retrieve all password…
Ucm6202 Firmware
1.0.20.22+
CRITICAL 9.8
CVE-2020-5722 KEVEPSS 84%
The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. An attacker c…
Ucm6200 Firmware
1.0.19.20+
CRITICAL 10.0
CVE-2013-3542
Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P, GXV3651FHD, GXV3662HD, GXV3615WP_HD, GXV3500, and possibly other camer…
Gxv3501 Firmware
Mitigation only
CRITICAL 9.8
CVE-2018-17564
A Malformed Input String to /cgi-bin/delete_CA on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to delete configuration parameters and g…
Gxp1610 Firmware
Mitigation only
CRITICAL 9.8
CVE-2018-17565
Shell Metacharacter Injection in the SSH configuration interface on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to execute arbitrary s…
Gxp1610 Firmware
Mitigation only
MEDIUM 5.3
CVE-2018-17563
A Malformed Input String to /cgi-bin/api-get_line_status on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to dump the device's configura…
Gxp1610 Firmware
Mitigation only