CRITICAL🇵🇱 Wersja polska

CVE-2018-17565

CVSS 9.8v3.0pub. 2019-04-01upd. 2024-11-21

Shell Metacharacter Injection in the SSH configuration interface on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to execute arbitrary system commands and gain a root shell.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Grandstream Gxp1610

    HW
    Grandstream
    all versions
  • Grandstream Gxp1610 Firmware

    OS
    Grandstream
    1.0.4.128
  • Grandstream Gxp1615

    HW
    Grandstream
    all versions
  • Grandstream Gxp1615 Firmware

    OS
    Grandstream
    1.0.4.128
  • Grandstream Gxp1620

    HW
    Grandstream
    all versions
  • Grandstream Gxp1620 Firmware

    OS
    Grandstream
    1.0.4.128
  • Grandstream Gxp1625

    HW
    Grandstream
    all versions
  • Grandstream Gxp1625 Firmware

    OS
    Grandstream
    1.0.4.128
  • Grandstream Gxp1628

    HW
    Grandstream
    all versions
  • Grandstream Gxp1628 Firmware

    OS
    Grandstream
    1.0.4.128
  • Grandstream Gxp1630

    HW
    Grandstream
    all versions
  • Grandstream Gxp1630 Firmware

    OS
    Grandstream
    1.0.4.128
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2026-2329CRITICAL9.3PL ✓same product

Krytyczny stack-based buffer overflow w telefonach VoIP Grandstream GXP16xx

CVE-2018-17564CRITICAL9.8PL ✓same product

Grandstream GXP16xx VoIP — usunięcie konfiguracji i przejęcie konta admina

CVE-2025-28170HIGH7.6same product

Grandstream Networks GXP1628 <=1.0.4.130 is vulnerable to Incorrect Access Control. The device is configured w...

CVE-2020-5738HIGH8.8same product

Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command executio...

CVE-2020-5739HIGH8.8same product

Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command executio...