Shell Metacharacter Injection in the SSH configuration interface on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to execute arbitrary system commands and gain a root shell.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HGrandstream Gxp1610
HWGrandstreamall versionsGrandstream Gxp1610 Firmware
OSGrandstream1.0.4.128Grandstream Gxp1615
HWGrandstreamall versionsGrandstream Gxp1615 Firmware
OSGrandstream1.0.4.128Grandstream Gxp1620
HWGrandstreamall versionsGrandstream Gxp1620 Firmware
OSGrandstream1.0.4.128Grandstream Gxp1625
HWGrandstreamall versionsGrandstream Gxp1625 Firmware
OSGrandstream1.0.4.128Grandstream Gxp1628
HWGrandstreamall versionsGrandstream Gxp1628 Firmware
OSGrandstream1.0.4.128Grandstream Gxp1630
HWGrandstreamall versionsGrandstream Gxp1630 Firmware
OSGrandstream1.0.4.128
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
CWE
Related vulnerabilities
CVE-2026-2329CRITICAL9.3PL ✓same product
Krytyczny stack-based buffer overflow w telefonach VoIP Grandstream GXP16xx
CVE-2018-17564CRITICAL9.8PL ✓same product
Grandstream GXP16xx VoIP — usunięcie konfiguracji i przejęcie konta admina
CVE-2025-28170HIGH7.6same product
Grandstream Networks GXP1628 <=1.0.4.130 is vulnerable to Incorrect Access Control. The device is configured w...
CVE-2020-5738HIGH8.8same product
Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command executio...
CVE-2020-5739HIGH8.8same product
Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command executio...