Vulnerability index

Browse CVEs

54 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2019-10655EPSS 15% Grandstream GAC2500 1.0.3.35, GXP2200 1.0.3.27, GVC3202 1.0.3.51, GXV3275 before 1.0.3.219 Beta, and GXV3240 before 1.0.3.219 Beta devices allow unau… Gac2500 Firmware 1.0.3.51 / 1.0.3.219+ Fix from $2,3002019-03-30 CRITICAL 9.8 CVE-2019-10661 On Grandstream GXV3611IR_HD before 1.0.3.23 devices, the root account lacks a password. Gxv3611ir Hd Firmware 1.0.3.23+ Fix from $2,3002019-03-30 HIGH 8.8 CVE-2019-10656 Grandstream GWN7000 before 1.0.6.32 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filename in a … Gwn7000 Firmware 1.0.6.32+ Fix from $1,9502019-03-30 HIGH 8.8 CVE-2019-10658 Grandstream GWN7610 before 1.0.8.18 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filename in a … Gwn7610 Firmware 1.0.8.18+ Fix from $1,9502019-03-30 HIGH 8.8 CVE-2019-10659 Grandstream GXV3370 before 1.0.1.41 and WP820 before 1.0.3.6 devices allow remote authenticated users to execute arbitrary code via shell metacharact… Gxv3370 Firmware 1.0.1.41 / 1.0.3.6+ Fix from $1,9502019-03-30 HIGH 8.8 CVE-2019-10660 Grandstream GXV3611IR_HD before 1.0.3.23 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the /goform/s… Gxv3611ir Hd Firmware 1.0.3.23+ Fix from $1,9502019-03-30 HIGH 8.8 CVE-2019-10662EPSS 44% Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the backupUCMConf… Ucm6204 Firmware 1.0.19.20+ Fix from $1,9502019-03-30 HIGH 8.8 CVE-2019-10663EPSS 28% Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to conduct SQL injection attacks via the sord parameter in a listCodebl… Ucm6204 Firmware 1.0.19.20+ Fix from $1,9502019-03-30 MEDIUM 6.5 CVE-2019-10657 Grandstream GWN7000 before 1.0.6.32 and GWN7610 before 1.0.8.18 devices allow remote authenticated users to discover passwords via a /ubus/uci.apply … Gwn7610 Firmware 1.0.6.32 / 1.0.8.18+ Fix from $1,6002019-03-30 HIGH 8.8 CVE-2017-16565 Cross-Site Request Forgery (CSRF) in /cgi-bin/login on Vonage (Grandstream) HT802 devices allows attackers to authenticate a user via the login scree… Ht802 Firmware No fix yet Fix from $1,9502017-11-06 HIGH 8.0 CVE-2017-16563 Cross-Site Request Forgery (CSRF) in the Basic Settings screen on Vonage (Grandstream) HT802 devices allows attackers to modify settings, related to … Ht802 Firmware No fix yet Fix from $1,9502017-11-06 MEDIUM 5.4 CVE-2017-16564 Stored Cross-site scripting (XSS) vulnerability in /cgi-bin/config2 on Vonage (Grandstream) HT802 devices allows remote authenticated users to inject… Ht802 Firmware No fix yet Fix from $1,6002017-11-06 HIGH 8.1 CVE-2016-1518 The auto-provisioning mechanism in the Grandstream Wave app 1.0.1.26 and earlier for Android and Grandstream Video IP phones allows man-in-the-middle… Wave after 1.0.1.26 Fix from $1,9502017-04-21 HIGH 7.8 CVE-2016-1520 The Grandstream Wave app 1.0.1.26 and earlier for Android does not use HTTPS when retrieving update information, which might allow man-in-the-middle … Wave after 1.0.1.26 Fix from $1,9502017-04-21 MEDIUM 5.9 CVE-2016-1519 The com.softphone.common package in the Grandstream Wave app 1.0.1.26 and earlier for Android does not properly validate SSL certificates, which allo… Wave after 1.0.1.26 Fix from $1,6002017-04-21 HIGH 7.5 CVE-2015-2866 SQL injection vulnerability on the Grandstream GXV3611_HD camera with firmware before 1.0.3.9 beta allows remote attackers to execute arbitrary SQL c… Gxv3611 Hd Firmware after 1.0.3.6 Fix from $1,9502015-07-08 MEDIUM 6.8 CVE-2013-3963 Cross-site request forgery (CSRF) vulnerability in goform/usermanage in Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P… Gxv Device Firmware after 1.0.4.43 Fix from $1,6002013-10-01 HIGH 7.8 CVE-2007-5789 The Grandstream HT-488 0.1 allows remote attackers to cause a denial of service (device crash) via a flood of fragmented packets to port 5060. Ht488 Mitigation only Fix from $1,9502007-11-01 HIGH 7.1 CVE-2007-5788 Buffer overflow in the SIP parser on the Grandstream HT-488 0.1 allows remote attackers to cause a denial of service (device crash) via a crafted SIP… Ht488 Mitigation only Fix from $1,9502007-11-01 HIGH 7.8 CVE-2007-4498EPSS 14% The Grandstream SIP Phone GXV-3000 with firmware 1.0.1.7, Loader 1.0.0.6, and Boot 1.0.0.18 allows remote attackers to force silent call completion, … Sip Phone No fix yet Fix from $1,9502007-08-23 HIGH 7.8 CVE-2007-1590 The Grandstream BudgeTone 200 IP phone, with program 1.1.1.14 and bootloader 1.1.1.5, allows remote attackers to cause a denial of service (device cr… Budgetone 200 Mitigation only Fix from $1,9502007-03-21 HIGH 7.8 CVE-2006-5231 Grandstream GXP-2000 VoIP Desktop Phone, firmware version 1.1.0.5, allows remote attackers to cause a denial of service (hang or reboot) via a large … Gxp 2000 Patch available Fix from $1,9502006-10-11 MEDIUM 5.0 CVE-2005-2581 Grandstream BudgeTone 101 and 102 running firmware 1.0.6.7 and possibly earlier versions, allows remote attackers to cause a denial of service (devic… Budgetone 101 after 1.0.6.7 Fix from $1,6002005-08-16 HIGH 7.5 CVE-2005-2182 Grandstream BudgeTone (BT) 100 Voice over IP (VoIP) phones do not properly check the Call-ID, branch, and tag values in a NOTIFY message to verify a … Bt 100 Firmware Mitigation only Fix from $1,9502005-07-11