CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
SINGLE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:L/Au:S/C:C/I:C/A:C
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
65.6%
Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker adds an OpenVPN up script to the phone’s VPN settings via the “Additional Settings” field in the web interface. When the VPN’s connection is established, the user defined script is executed with root privileges.
Vendor | Product | Version | CPE |
---|---|---|---|
grandstream | gxp1610_firmware | * | cpe:2.3:o:grandstream:gxp1610_firmware:*:*:*:*:*:*:*:* |
grandstream | gxp1610 | - | cpe:2.3:h:grandstream:gxp1610:-:*:*:*:*:*:*:* |
grandstream | gxp1615_firmware | * | cpe:2.3:o:grandstream:gxp1615_firmware:*:*:*:*:*:*:*:* |
grandstream | gxp1615 | - | cpe:2.3:h:grandstream:gxp1615:-:*:*:*:*:*:*:* |
grandstream | gxp1620_firmware | * | cpe:2.3:o:grandstream:gxp1620_firmware:*:*:*:*:*:*:*:* |
grandstream | gxp1620 | - | cpe:2.3:h:grandstream:gxp1620:-:*:*:*:*:*:*:* |
grandstream | gxp1625_firmware | * | cpe:2.3:o:grandstream:gxp1625_firmware:*:*:*:*:*:*:*:* |
grandstream | gxp1625 | - | cpe:2.3:h:grandstream:gxp1625:-:*:*:*:*:*:*:* |
grandstream | gxp1628_firmware | * | cpe:2.3:o:grandstream:gxp1628_firmware:*:*:*:*:*:*:*:* |
grandstream | gxp1628 | - | cpe:2.3:h:grandstream:gxp1628:-:*:*:*:*:*:*:* |
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
SINGLE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:L/Au:S/C:C/I:C/A:C
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
65.6%