← Back

Grandstream

grandstream

55 CVEs • 113 products

Products (113)

Click to collapse
Toggle
Wave
wave
Ht488
ht488
Gxv3500
gxv3500
Gxv3501
gxv3501
Gxv3504
gxv3504
Gxv3601
gxv3601
Gxv3601hd/ll
gxv3601hd/ll
Gxv3611hd/ll
gxv3611hd/ll
Gxv3615w/p
gxv3615w/p
Gxv3615wp Hd
gxv3615wp_hd
Gxv3651fhd
gxv3651fhd
Gxv3662hd
gxv3662hd
Budgetone 101
budgetone_101
Budgetone 102
budgetone_102
Gxp 2000
gxp-2000
Budgetone 200
budgetone_200
Sip Phone
sip_phone
Wp820 Firmware
wp820_firmware
Bt 100
bt-100
Gxv3611 Hd
gxv3611_hd
Ht802
ht802
Gac2500
gac2500
Gvc3202
gvc3202
Gxv3275
gxv3275
Gxv3240
gxv3240
Gxp2200
gxp2200
Gwn7000
gwn7000
Gwn7610
gwn7610
Gxv3370
gxv3370
Wp820
wp820
Gxv3611ir Hd
gxv3611ir_hd
Ucm6204
ucm6204
Gxp1610
gxp1610
Gxp1615
gxp1615
Gxp1620
gxp1620
Gxp1625
gxp1625
Gxp1628
gxp1628
Gxp1630
gxp1630
Gxv3601hd
gxv3601hd
Gxv3601ll
gxv3601ll
Gxv3611hd
gxv3611hd
Gxv3611ll
gxv3611ll
Gxv3615w
gxv3615w
Gxv3615p
gxv3615p
Ucm6200
ucm6200
Ucm6202
ucm6202
Ucm6208
ucm6208
Ht801
ht801
Ht812
ht812

CVEs (55)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Grandstream
6Gxp1610 Firmware
Gxp1615 FirmwareGxp1620 Firmware+3 more
Jun 17, 2026
Feb 18, 2026
9.3 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
An unauthenticated stack-based buffer overflow vulnerability exists in the HTTP API endpoint /cgi-bin/api.values.get. A remote attacker can leverage this vulnerability to achieve unauthenticated remote code execution (RC...Show more
An unauthenticated stack-based buffer overflow vulnerability exists in the HTTP API endpoint /cgi-bin/api.values.get. A remote attacker can leverage this vulnerability to achieve unauthenticated remote code execution (RCE) with root privileges on a target device. The vulnerability affects all six device models in the series: GXP1610, GXP1615, GXP1620, GXP1625, GXP1628, and GXP1630.Show less
1Grandstream
1Gxp1628 Firmware
Jul 5, 2026
Jul 29, 2025
N/A· v4
7.6 HIGH· v3
N/A· v2
Grandstream Networks GXP1628 <=1.0.4.130 is vulnerable to Incorrect Access Control. The device is configured with directory listing enabled, allowing unauthorized access to sensitive directories and files.
1Grandstream
1Ucm6510 Firmware
Jul 5, 2026
Jul 29, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue in Grandstream UCM6510 v.1.0.20.52 and before allows a remote attacker to obtain sensitive information via the Login function at /cgi and /webrtccgi.
1Grandstream
1Ucm6510 Firmware
Jul 5, 2026
Jul 29, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Grandstream Networks UCM6510 v1.0.20.52 and before is vulnerable to Improper Restriction of Excessive Authentication Attempts. An attacker can perform an arbitrary number of authentication attempts using different passwo...Show more
Grandstream Networks UCM6510 v1.0.20.52 and before is vulnerable to Improper Restriction of Excessive Authentication Attempts. An attacker can perform an arbitrary number of authentication attempts using different passwords and eventually gain access to the targeted account using a brute force attack.Show less
1Grandstream
1Gxp2135 Firmware
Jun 17, 2026
Jul 3, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An os command injection vulnerability exists in the CWMP SelfDefinedTimeZone functionality of Grandstream GXP2135 1.0.9.129, 1.0.11.74 and 1.0.11.79. A specially crafted network packet can lead to arbitrary command execu...Show more
An os command injection vulnerability exists in the CWMP SelfDefinedTimeZone functionality of Grandstream GXP2135 1.0.9.129, 1.0.11.74 and 1.0.11.79. A specially crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of malicious packets to trigger this vulnerability.Show less
1Grandstream
1Gds3710 Firmware
Jun 17, 2026
Sep 23, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In Grandstream GSD3710 in its 1.0.11.13 version, it's possible to overflow the stack since it doesn't check the param length before using the sscanf instruction. Because of that, an attacker could create a socket and con...Show more
In Grandstream GSD3710 in its 1.0.11.13 version, it's possible to overflow the stack since it doesn't check the param length before using the sscanf instruction. Because of that, an attacker could create a socket and connect with a remote IP:port by opening a shell and getting full access to the system. The exploit affects daemons dbmng and logsrv that are running on ports 8000 and 8001 by default.Show less
1Grandstream
1Gds3710 Firmware
Jun 17, 2026
Sep 23, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
an attacker with knowledge of user/pass of Grandstream GSD3710 in its 1.0.11.13 version, could overflow the stack since it doesn't check the param length before use the strcopy instruction. The explotation of this vulner...Show more
an attacker with knowledge of user/pass of Grandstream GSD3710 in its 1.0.11.13 version, could overflow the stack since it doesn't check the param length before use the strcopy instruction. The explotation of this vulnerability may lead an attacker to execute a shell with full access.Show less
1Grandstream
1Ht801 Firmware
Jun 17, 2026
Oct 28, 2021
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
An issue was discovered on the Grandstream HT801 Analog Telephone Adaptor before 1.0.29.8. From the limited configuration shell, it is possible to set the malicious gdb_debug_server variable. As a result, after a reboot,...Show more
An issue was discovered on the Grandstream HT801 Analog Telephone Adaptor before 1.0.29.8. From the limited configuration shell, it is possible to set the malicious gdb_debug_server variable. As a result, after a reboot, the device downloads and executes malicious scripts from an attacker-defined host.Show less
1Grandstream
1Ht801 Firmware
Jun 17, 2026
Oct 28, 2021
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Multiple buffer overflows in the limited configuration shell (/sbin/gs_config) on Grandstream HT801 devices before 1.0.29 allow remote authenticated users to execute arbitrary code as root via a crafted manage_if setting...Show more
Multiple buffer overflows in the limited configuration shell (/sbin/gs_config) on Grandstream HT801 devices before 1.0.29 allow remote authenticated users to execute arbitrary code as root via a crafted manage_if setting, thus bypassing the intended restrictions of this shell and taking full control of the device. There are default weak credentials that can be used to authenticate.Show less
1Grandstream
7Grp2612 Firmware
Grp2612p FirmwareGrp2612w Firmware+4 more
Jun 17, 2026
Mar 29, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allow Authentication Bypass in its administrative web interface.
1Grandstream
7Grp2612 Firmware
Grp2612p FirmwareGrp2612w Firmware+4 more
Jun 17, 2026
Mar 29, 2021
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allows Command Injection as root in its administrative web interface.
1Grandstream
6Ht801 Firmware
Ht802 FirmwareHt812 Firmware+3 more
Jun 17, 2026
Jul 29, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Grandstream HT800 series firmware version 1.0.17.5 and below contain a backdoor in the SSH service. An authenticated remote attacker can obtain a root shell by correctly answering a challenge prompt.
1Grandstream
6Ht801 Firmware
Ht802 FirmwareHt812 Firmware+3 more
Jun 17, 2026
Jul 29, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to a denial of service attack against the TR-069 service. An unauthenticated remote attacker can stop the service due to a NULL pointer dereferen...Show more
Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to a denial of service attack against the TR-069 service. An unauthenticated remote attacker can stop the service due to a NULL pointer dereference in the TR-069 service. This condition is triggered due to mishandling of the HTTP Authentication field.Show less
1Grandstream
6Ht801 Firmware
Ht802 FirmwareHt812 Firmware+3 more
Jun 17, 2026
Jul 29, 2020
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to CPU exhaustion due to an infinite loop in the TR-069 service. Unauthenticated remote attackers can trigger this case by sending a one characte...Show more
Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to CPU exhaustion due to an infinite loop in the TR-069 service. Unauthenticated remote attackers can trigger this case by sending a one character TCP message to the TR-069 service.Show less
1Grandstream
6Ht801 Firmware
Ht802 FirmwareHt812 Firmware+3 more
Jun 17, 2026
Jul 29, 2020
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to an OS command injection vulnerability. Unauthenticated remote attackers can execute arbitrary commands as root by crafting a special configura...Show more
Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to an OS command injection vulnerability. Unauthenticated remote attackers can execute arbitrary commands as root by crafting a special configuration file and sending a crafted SIP message.Show less
1Grandstream
3Ucm6202 Firmware
Ucm6204 FirmwareUcm6208 Firmware
Jun 17, 2026
Jul 17, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via SSH. An authenticated remote attacker can execute commands as the root user by issuing a specially crafted "unset"...Show more
Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via SSH. An authenticated remote attacker can execute commands as the root user by issuing a specially crafted "unset" command.Show less
1Grandstream
3Ucm6202 Firmware
Ucm6204 FirmwareUcm6208 Firmware
Jun 17, 2026
Jul 17, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authenticated remote attacker can execute commands as the root user by sending a crafted HTTP GET to the...Show more
Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authenticated remote attacker can execute commands as the root user by sending a crafted HTTP GET to the UCM's "Old" HTTPS API.Show less
1Grandstream
3Ucm6202 Firmware
Ucm6204 FirmwareUcm6208 Firmware
Jun 17, 2026
Jul 17, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authenticated remote attacker can bypass command injection mitigations and execute commands as the root u...Show more
Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authenticated remote attacker can bypass command injection mitigations and execute commands as the root user by sending a crafted HTTP POST to the UCM's "New" HTTPS API.Show less
1Grandstream
1Gwn7000 Firmware
Jun 17, 2026
Jul 17, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Grandstream GWN7000 firmware version 1.0.9.4 and below allows authenticated remote users to modify the system's crontab via undocumented API. An attacker can use this functionality to execute arbitrary OS commands on the...Show more
Grandstream GWN7000 firmware version 1.0.9.4 and below allows authenticated remote users to modify the system's crontab via undocumented API. An attacker can use this functionality to execute arbitrary OS commands on the router.Show less
1Grandstream
6Gxp1610 Firmware
Gxp1615 FirmwareGxp1620 Firmware+3 more
Jun 17, 2026
Apr 14, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker adds an OpenVPN up script to the phone's VPN settings via the "Additional Settings" field i...Show more
Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker adds an OpenVPN up script to the phone's VPN settings via the "Additional Settings" field in the web interface. When the VPN's connection is established, the user defined script is executed with root privileges.Show less