HIGH🇵🇱 Wersja polska

CVE-2025-28170

CVSS 7.6v3.1pub. 2025-07-29upd. 2026-07-05

Grandstream Networks GXP1628 <=1.0.4.130 is vulnerable to Incorrect Access Control. The device is configured with directory listing enabled, allowing unauthorized access to sensitive directories and files.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
  • Grandstream Gxp1628

    HW
    Grandstream
    all versions
  • Grandstream Gxp1628 Firmware

    OS
    Grandstream
    ≤ 1.0.4.130
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-2329CRITICAL9.3PL ✓same product

Krytyczny stack-based buffer overflow w telefonach VoIP Grandstream GXP16xx

CVE-2018-17564CRITICAL9.8PL ✓same product

Grandstream GXP16xx VoIP — usunięcie konfiguracji i przejęcie konta admina

CVE-2018-17565CRITICAL9.8PL ✓same product

Command Injection w interfejsie SSH telefonów VoIP Grandstream GXP16xx

CVE-2020-5738HIGH8.8same product

Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command executio...

CVE-2020-5739HIGH8.8same product

Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command executio...