Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker uploads a specially crafted tar file to the HTTP /cgi-bin/upload_vpntar interface.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HGrandstream Gxp1610
HWGrandstreamall versionsGrandstream Gxp1610 Firmware
OSGrandstream≤ 1.0.4.152Grandstream Gxp1615
HWGrandstreamall versionsGrandstream Gxp1615 Firmware
OSGrandstream≤ 1.0.4.152Grandstream Gxp1620
HWGrandstreamall versionsGrandstream Gxp1620 Firmware
OSGrandstream≤ 1.0.4.152Grandstream Gxp1625
HWGrandstreamall versionsGrandstream Gxp1625 Firmware
OSGrandstream≤ 1.0.4.152Grandstream Gxp1628
HWGrandstreamall versionsGrandstream Gxp1628 Firmware
OSGrandstream≤ 1.0.4.152Grandstream Gxp1630
HWGrandstreamall versionsGrandstream Gxp1630 Firmware
OSGrandstream≤ 1.0.4.152
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
VPN
Related vulnerabilities
CVE-2026-2329CRITICAL9.3PL ✓same product
Krytyczny stack-based buffer overflow w telefonach VoIP Grandstream GXP16xx
CVE-2018-17564CRITICAL9.8PL ✓same product
Grandstream GXP16xx VoIP — usunięcie konfiguracji i przejęcie konta admina
CVE-2018-17565CRITICAL9.8PL ✓same product
Command Injection w interfejsie SSH telefonów VoIP Grandstream GXP16xx
CVE-2025-28170HIGH7.6same product
Grandstream Networks GXP1628 <=1.0.4.130 is vulnerable to Incorrect Access Control. The device is configured w...
CVE-2020-5739HIGH8.8same product
Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command executio...