← Back

CVE-2016-1519

nvd nist
Published: Apr 21, 2017Modified: May 13, 2026

JSON object

Loading...
5.9
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 2.2 / Impact: 3.6
Source: NVD

Description

The com.softphone.common package in the Grandstream Wave app 1.0.1.26 and earlier for Android does not properly validate SSL certificates, which allows man-in-the-middle attackers to spoof the Grandstream provisioning server via a crafted certificate.

Affected (1)

Products: Grandstream: Wave
1 product
Wave
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.0.1.26

Timeline

No history available yet.