Vulnerability index

Browse CVEs

54 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-2329EPSS 40% An unauthenticated stack-based buffer overflow vulnerability exists in the HTTP API endpoint /cgi-bin/api.values.get. A remote attacker can leverage … Gxp1610 Firmware 1.0.7.81+ Fix from $2,3002026-02-18 HIGH 7.6 CVE-2025-28170 Grandstream Networks GXP1628 <=1.0.4.130 is vulnerable to Incorrect Access Control. The device is configured with directory listing enabled, allowing… Gxp1628 Firmware after 1.0.4.130 Fix from $1,9502025-07-29 MEDIUM 6.5 CVE-2025-28171 An issue in Grandstream UCM6510 v.1.0.20.52 and before allows a remote attacker to obtain sensitive information via the Login function at /cgi and /w… Ucm6510 Firmware after 1.0.20.52 Fix from $1,6002025-07-29 MEDIUM 6.5 CVE-2025-28172 Grandstream Networks UCM6510 v1.0.20.52 and before is vulnerable to Improper Restriction of Excessive Authentication Attempts. An attacker can perfor… Ucm6510 Firmware after 1.0.20.52 Fix from $1,6002025-07-29 CRITICAL 9.8 CVE-2024-32937EPSS 26% An os command injection vulnerability exists in the CWMP SelfDefinedTimeZone functionality of Grandstream GXP2135 1.0.9.129, 1.0.11.74 and 1.0.11.79.… Gxp2135 Firmware No fix yet Fix from $2,3002024-07-03 CRITICAL 9.8 CVE-2022-2025 an attacker with knowledge of user/pass of Grandstream GSD3710 in its 1.0.11.13 version, could overflow the stack since it doesn't check the param le… Gds3710 Firmware Mitigation only Fix from $2,3002022-09-23 CRITICAL 9.8 CVE-2022-2070 In Grandstream GSD3710 in its 1.0.11.13 version, it's possible to overflow the stack since it doesn't check the param length before using the sscanf … Gds3710 Firmware Mitigation only Fix from $2,3002022-09-23 HIGH 8.8 CVE-2021-37748EPSS 7% Multiple buffer overflows in the limited configuration shell (/sbin/gs_config) on Grandstream HT801 devices before 1.0.29 allow remote authenticated … Ht801 Firmware 1.0.29+ Fix from $1,9502021-10-28 HIGH 8.8 CVE-2021-37915 An issue was discovered on the Grandstream HT801 Analog Telephone Adaptor before 1.0.29.8. From the limited configuration shell, it is possible to se… Ht801 Firmware 1.0.29.8+ Fix from $1,9502021-10-28 CRITICAL 9.8 CVE-2020-25218 Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allow Authentication Bypass in its administrative web interface. Grp2612 Firmware Mitigation only Fix from $2,3002021-03-29 HIGH 7.2 CVE-2020-25217 Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allows Command Injection as root in its administrative web interface. Grp2612 Firmware Mitigation only Fix from $1,9502021-03-29 HIGH 8.8 CVE-2020-5763 Grandstream HT800 series firmware version 1.0.17.5 and below contain a backdoor in the SSH service. An authenticated remote attacker can obtain a roo… Ht801 Firmware after 1.0.17.5 Fix from $1,9502020-07-29 HIGH 7.5 CVE-2020-5761 Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to CPU exhaustion due to an infinite loop in the TR-069 service. Unauthent… Ht801 Firmware after 1.0.17.5 Fix from $1,9502020-07-29 HIGH 7.5 CVE-2020-5762 Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to a denial of service attack against the TR-069 service. An unauthenticat… Ht801 Firmware after 1.0.17.5 Fix from $1,9502020-07-29 HIGH 7.8 CVE-2020-5760EPSS 5% Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to an OS command injection vulnerability. Unauthenticated remote attackers… Ht801 Firmware after 1.0.17.5 Fix from $1,9502020-07-29 CRITICAL 9.8 CVE-2020-5757EPSS 7% Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authenticated remote attacker can … Ucm6202 Firmware after 1.0.20.23 Fix from $2,3002020-07-17 CRITICAL 9.8 CVE-2020-5759 Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via SSH. An authenticated remote attacker can e… Ucm6202 Firmware after 1.0.20.23 Fix from $2,3002020-07-17 HIGH 8.8 CVE-2020-5756 Grandstream GWN7000 firmware version 1.0.9.4 and below allows authenticated remote users to modify the system's crontab via undocumented API. An atta… Gwn7000 Firmware after 1.0.9.4 Fix from $1,9502020-07-17 HIGH 8.8 CVE-2020-5758 Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authenticated remote attacker can … Ucm6202 Firmware after 1.0.20.23 Fix from $1,9502020-07-17 HIGH 8.8 CVE-2020-5739EPSS 5% Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker adds an OpenVPN up s… Gxp1610 Firmware after 1.0.4.152 Fix from $1,9502020-04-14 HIGH 8.8 CVE-2020-5738EPSS 5% Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker uploads a specially … Gxp1610 Firmware after 1.0.4.152 Fix from $1,9502020-04-14 HIGH 7.5 CVE-2020-5724EPSS 12% The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpoint. A remote unauthenticated… Ucm6202 Firmware 1.0.20.22+ Fix from $1,9502020-03-30 HIGH 7.5 CVE-2020-5726 The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the CTI server on port 8888. A remote unauthenticated attacker … Ucm6202 Firmware 1.0.20.22+ Fix from $1,9502020-03-30 MEDIUM 5.9 CVE-2020-5725 The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpoint. A remote unauthenticated… Ucm6202 Firmware 1.0.20.22+ Fix from $1,6002020-03-30 CRITICAL 9.8 CVE-2020-5723EPSS 6% The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database. This could allow an attacker to retrieve all password… Ucm6202 Firmware 1.0.20.22+ Fix from $2,3002020-03-30 CRITICAL 9.8 CVE-2020-5722 KEVEPSS 84% The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. An attacker c… Ucm6200 Firmware 1.0.19.20+ Fix from $2,3002020-03-23 CRITICAL 10.0 CVE-2013-3542 Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P, GXV3651FHD, GXV3662HD, GXV3615WP_HD, GXV3500, and possibly other camer… Gxv3501 Firmware Mitigation only Fix from $2,3002019-12-11 CRITICAL 9.8 CVE-2018-17564 A Malformed Input String to /cgi-bin/delete_CA on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to delete configuration parameters and g… Gxp1610 Firmware Mitigation only Fix from $2,3002019-04-01 CRITICAL 9.8 CVE-2018-17565 Shell Metacharacter Injection in the SSH configuration interface on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to execute arbitrary s… Gxp1610 Firmware Mitigation only Fix from $2,3002019-04-01 MEDIUM 5.3 CVE-2018-17563 A Malformed Input String to /cgi-bin/api-get_line_status on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to dump the device's configura… Gxp1610 Firmware Mitigation only Fix from $1,6002019-04-01