← Back

Grandstream

grandstream

55 CVEs • 113 products

Products (113)

Click to collapse
Toggle
Wave
wave
Ht488
ht488
Gxv3500
gxv3500
Gxv3501
gxv3501
Gxv3504
gxv3504
Gxv3601
gxv3601
Gxv3601hd/ll
gxv3601hd/ll
Gxv3611hd/ll
gxv3611hd/ll
Gxv3615w/p
gxv3615w/p
Gxv3615wp Hd
gxv3615wp_hd
Gxv3651fhd
gxv3651fhd
Gxv3662hd
gxv3662hd
Budgetone 101
budgetone_101
Budgetone 102
budgetone_102
Gxp 2000
gxp-2000
Budgetone 200
budgetone_200
Sip Phone
sip_phone
Wp820 Firmware
wp820_firmware
Bt 100
bt-100
Gxv3611 Hd
gxv3611_hd
Ht802
ht802
Gac2500
gac2500
Gvc3202
gvc3202
Gxv3275
gxv3275
Gxv3240
gxv3240
Gxp2200
gxp2200
Gwn7000
gwn7000
Gwn7610
gwn7610
Gxv3370
gxv3370
Wp820
wp820
Gxv3611ir Hd
gxv3611ir_hd
Ucm6204
ucm6204
Gxp1610
gxp1610
Gxp1615
gxp1615
Gxp1620
gxp1620
Gxp1625
gxp1625
Gxp1628
gxp1628
Gxp1630
gxp1630
Gxv3601hd
gxv3601hd
Gxv3601ll
gxv3601ll
Gxv3611hd
gxv3611hd
Gxv3611ll
gxv3611ll
Gxv3615w
gxv3615w
Gxv3615p
gxv3615p
Ucm6200
ucm6200
Ucm6202
ucm6202
Ucm6208
ucm6208
Ht801
ht801
Ht812
ht812

CVEs (55)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Grandstream
6Gxp1610 Firmware
Gxp1615 FirmwareGxp1620 Firmware+3 more
Jun 17, 2026
Apr 14, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker uploads a specially crafted tar file to the HTTP /cgi-bin/upload_vpntar interface.
1Grandstream
3Ucm6202 Firmware
Ucm6204 FirmwareUcm6208 Firmware
Jun 17, 2026
Mar 30, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the CTI server on port 8888. A remote unauthenticated attacker can invoke the challenge action with a crafted username and discover us...Show more
The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the CTI server on port 8888. A remote unauthenticated attacker can invoke the challenge action with a crafted username and discover user passwords.Show less
1Grandstream
3Ucm6202 Firmware
Ucm6204 FirmwareUcm6208 Firmware
Jun 17, 2026
Mar 30, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpoint. A remote unauthenticated attacker can invoke the login action with a crafted username and, thro...Show more
The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpoint. A remote unauthenticated attacker can invoke the login action with a crafted username and, through the use of timing attacks, can discover user passwords.Show less
1Grandstream
3Ucm6202 Firmware
Ucm6204 FirmwareUcm6208 Firmware
Jun 17, 2026
Mar 30, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpoint. A remote unauthenticated attacker can invoke the challenge action with a crafted username and d...Show more
The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpoint. A remote unauthenticated attacker can invoke the challenge action with a crafted username and discover user passwords.Show less
1Grandstream
3Ucm6202 Firmware
Ucm6204 FirmwareUcm6208 Firmware
Jun 17, 2026
Mar 30, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database. This could allow an attacker to retrieve all passwords and possibly gain elevated privileges.
1Grandstream
1Ucm6200 Firmware
Jun 17, 2026
Mar 23, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. An attacker can use this vulnerability to execute shell commands as root on versions...Show more
The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. An attacker can use this vulnerability to execute shell commands as root on versions before 1.0.19.20 or inject HTML in password recovery emails in versions before 1.0.20.17.Show less
1Grandstream
13Gxv3500 Firmware
Gxv3501 FirmwareGxv3504 Firmware+10 more
Nov 21, 2024
Dec 11, 2019
N/A· v4
10.0 CRITICAL· v3
10.0 HIGH· v2
Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P, GXV3651FHD, GXV3662HD, GXV3615WP_HD, GXV3500, and possibly other camera models with firmware 1.0.4.11, have a hardcoded account "!#/" with th...Show more
Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P, GXV3651FHD, GXV3662HD, GXV3615WP_HD, GXV3500, and possibly other camera models with firmware 1.0.4.11, have a hardcoded account "!#/" with the same password, which makes it easier for remote attackers to obtain access via a TELNET session.Show less
1Grandstream
6Gxp1610 Firmware
Gxp1615 FirmwareGxp1620 Firmware+3 more
Nov 21, 2024
Apr 1, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Shell Metacharacter Injection in the SSH configuration interface on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to execute arbitrary system commands and gain a root shell.
1Grandstream
6Gxp1610 Firmware
Gxp1615 FirmwareGxp1620 Firmware+3 more
Nov 21, 2024
Apr 1, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A Malformed Input String to /cgi-bin/delete_CA on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to delete configuration parameters and gain admin access to the device.
1Grandstream
6Gxp1610 Firmware
Gxp1615 FirmwareGxp1620 Firmware+3 more
Nov 21, 2024
Apr 1, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A Malformed Input String to /cgi-bin/api-get_line_status on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to dump the device's configuration in cleartext.
1Grandstream
1Ucm6204 Firmware
Jun 17, 2026
Mar 30, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to conduct SQL injection attacks via the sord parameter in a listCodeblueGroup API call to the /cgi? URI.
1Grandstream
1Ucm6204 Firmware
Jun 17, 2026
Mar 30, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the backupUCMConfig file-backup parameter to the /cgi? URI.
1Grandstream
1Gxv3611ir Hd Firmware
Jun 17, 2026
Mar 30, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
On Grandstream GXV3611IR_HD before 1.0.3.23 devices, the root account lacks a password.
1Grandstream
1Gxv3611ir Hd Firmware
Jun 17, 2026
Mar 30, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Grandstream GXV3611IR_HD before 1.0.3.23 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the /goform/systemlog?cmd=set logserver field.
1Grandstream
2Gxv3370 Firmware
Wp820 Firmware
Jun 17, 2026
Mar 30, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Grandstream GXV3370 before 1.0.1.41 and WP820 before 1.0.3.6 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in a /manager?action=getlogcat priority field.
1Grandstream
1Gwn7610 Firmware
Jun 17, 2026
Mar 30, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Grandstream GWN7610 before 1.0.8.18 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filename in a /ubus/controller.icc.update_nds_webroot_from_tmp update_nds_webroot_fro...Show more
Grandstream GWN7610 before 1.0.8.18 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filename in a /ubus/controller.icc.update_nds_webroot_from_tmp update_nds_webroot_from_tmp API call.Show less
1Grandstream
2Gwn7000 Firmware
Gwn7610 Firmware
Jun 17, 2026
Mar 30, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Grandstream GWN7000 before 1.0.6.32 and GWN7610 before 1.0.8.18 devices allow remote authenticated users to discover passwords via a /ubus/uci.apply config request.
1Grandstream
1Gwn7000 Firmware
Jun 17, 2026
Mar 30, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Grandstream GWN7000 before 1.0.6.32 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filename in a /ubus/uci.apply update_nds_webroot_from_tmp API call.
1Grandstream
5Gac2500 Firmware
Gvc3202 FirmwareGxp2200 Firmware+2 more
Jun 17, 2026
Mar 30, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Grandstream GAC2500 1.0.3.35, GXP2200 1.0.3.27, GVC3202 1.0.3.51, GXV3275 before 1.0.3.219 Beta, and GXV3240 before 1.0.3.219 Beta devices allow unauthenticated remote code execution via shell metacharacters in a /manage...Show more
Grandstream GAC2500 1.0.3.35, GXP2200 1.0.3.27, GVC3202 1.0.3.51, GXV3275 before 1.0.3.219 Beta, and GXV3240 before 1.0.3.219 Beta devices allow unauthenticated remote code execution via shell metacharacters in a /manager?action=getlogcat priority field, in conjunction with a buffer overflow (via the phonecookie cookie) to overwrite a data structure and consequently bypass authentication. This can be exploited remotely or via CSRF because the cookie can be placed in an Accept HTTP header in an XMLHttpRequest call to lighttpd.Show less
1Grandstream
1Ht802 Firmware
May 13, 2026
Nov 6, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-Site Request Forgery (CSRF) in /cgi-bin/login on Vonage (Grandstream) HT802 devices allows attackers to authenticate a user via the login screen using the default password of 123 and submit arbitrary requests.