VendorsGrandstreamgxp1625_firmware1.0.4.128
Vulnerabilities

Grandstream GXP1625 Firmware 1.0.4.128

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2018-17565
Shell Metacharacter Injection in the SSH configuration interface on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to execute arbitrary system commands and gain a root shell.
Published 2019-04-01 · Modified
10.0EPSS 0.019
CVE-2018-17564
A Malformed Input String to /cgi-bin/delete_CA on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to delete configuration parameters and gain admin access to the device.
Published 2019-04-01 · Modified
9.8EPSS 0.016
CVE-2018-17563
A Malformed Input String to /cgi-bin/api-get_line_status on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to dump the device's configuration in cleartext.
Published 2019-04-01 · Modified
5.3EPSS 0.007