CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2026-2329

CVSS 9.3v4.0pub. 2026-02-18upd. 2026-02-20

An unauthenticated stack-based buffer overflow vulnerability exists in the HTTP API endpoint /cgi-bin/api.values.get. A remote attacker can leverage this vulnerability to achieve unauthenticated remote code execution (RCE) with root privileges on a target device. The vulnerability affects all six device models in the series: GXP1610, GXP1615, GXP1620, GXP1625, GXP1628, and GXP1630.

🤖 AI Analysis
How it works

The vulnerability (CWE-121) consists of a stack buffer overflow via a malformed HTTP request to the /cgi-bin/api.values.get endpoint. The request handling process does not properly verify the length of input data, allowing an attacker to overwrite data on the stack and seize control of program execution flow. The attack requires no authentication or user interaction, and can be conducted remotely over the network.

Impact

An attacker can gain full control of the device by executing arbitrary code with root privileges (RCE), granting unlimited access to VoIP phone functions, call interception, and potential use of the device as an entry point into the internal network.

Mitigation & patch

Firmware must be immediately updated to version 1.0.7.81 or higher, available from the manufacturer (Release Note GXP16xx 1.0.7.81). Until the update is applied, it is recommended to restrict access to the HTTP interface of devices exclusively to trusted networks or VLAN segments and implement firewall rules blocking unauthorized access to administrative ports.

Who is affected

All six models in the GXP1600 series: GXP1610, GXP1615, GXP1620, GXP1625, GXP1628, and GXP1630 (firmware in all vulnerable versions — details in manufacturer's release notes). The patched firmware version is 1.0.7.81 or newer.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Grandstream Gxp1610

    HW
    Grandstream
    all versions
  • Grandstream Gxp1610 Firmware

    OS
    Grandstream
    < 1.0.7.81
  • Grandstream Gxp1615

    HW
    Grandstream
    all versions
  • Grandstream Gxp1615 Firmware

    OS
    Grandstream
    < 1.0.7.81
  • Grandstream Gxp1620

    HW
    Grandstream
    all versions
  • Grandstream Gxp1620 Firmware

    OS
    Grandstream
    < 1.0.7.81
  • Grandstream Gxp1625

    HW
    Grandstream
    all versions
  • Grandstream Gxp1625 Firmware

    OS
    Grandstream
    < 1.0.7.81
  • Grandstream Gxp1628

    HW
    Grandstream
    all versions
  • Grandstream Gxp1628 Firmware

    OS
    Grandstream
    < 1.0.7.81
  • Grandstream Gxp1630

    HW
    Grandstream
    all versions
  • Grandstream Gxp1630 Firmware

    OS
    Grandstream
    < 1.0.7.81
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCEMemory
CWE
References

Related vulnerabilities

CVE-2018-17564CRITICAL9.8PL ✓same product

Grandstream GXP16xx VoIP — usunięcie konfiguracji i przejęcie konta admina

CVE-2018-17565CRITICAL9.8PL ✓same product

Command Injection w interfejsie SSH telefonów VoIP Grandstream GXP16xx

CVE-2025-28170HIGH7.6same product

Grandstream Networks GXP1628 <=1.0.4.130 is vulnerable to Incorrect Access Control. The device is configured w...

CVE-2020-5738HIGH8.8same product

Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command executio...

CVE-2020-5739HIGH8.8same product

Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command executio...