An unauthenticated stack-based buffer overflow vulnerability exists in the HTTP API endpoint /cgi-bin/api.values.get. A remote attacker can leverage this vulnerability to achieve unauthenticated remote code execution (RCE) with root privileges on a target device. The vulnerability affects all six device models in the series: GXP1610, GXP1615, GXP1620, GXP1625, GXP1628, and GXP1630.
The vulnerability (CWE-121) consists of a stack buffer overflow via a malformed HTTP request to the /cgi-bin/api.values.get endpoint. The request handling process does not properly verify the length of input data, allowing an attacker to overwrite data on the stack and seize control of program execution flow. The attack requires no authentication or user interaction, and can be conducted remotely over the network.
An attacker can gain full control of the device by executing arbitrary code with root privileges (RCE), granting unlimited access to VoIP phone functions, call interception, and potential use of the device as an entry point into the internal network.
Firmware must be immediately updated to version 1.0.7.81 or higher, available from the manufacturer (Release Note GXP16xx 1.0.7.81). Until the update is applied, it is recommended to restrict access to the HTTP interface of devices exclusively to trusted networks or VLAN segments and implement firewall rules blocking unauthorized access to administrative ports.
All six models in the GXP1600 series: GXP1610, GXP1615, GXP1620, GXP1625, GXP1628, and GXP1630 (firmware in all vulnerable versions — details in manufacturer's release notes). The patched firmware version is 1.0.7.81 or newer.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XGrandstream Gxp1610
HWGrandstreamall versionsGrandstream Gxp1610 Firmware
OSGrandstream< 1.0.7.81Grandstream Gxp1615
HWGrandstreamall versionsGrandstream Gxp1615 Firmware
OSGrandstream< 1.0.7.81Grandstream Gxp1620
HWGrandstreamall versionsGrandstream Gxp1620 Firmware
OSGrandstream< 1.0.7.81Grandstream Gxp1625
HWGrandstreamall versionsGrandstream Gxp1625 Firmware
OSGrandstream< 1.0.7.81Grandstream Gxp1628
HWGrandstreamall versionsGrandstream Gxp1628 Firmware
OSGrandstream< 1.0.7.81Grandstream Gxp1630
HWGrandstreamall versionsGrandstream Gxp1630 Firmware
OSGrandstream< 1.0.7.81
Related vulnerabilities
Grandstream GXP16xx VoIP — usunięcie konfiguracji i przejęcie konta admina
Command Injection w interfejsie SSH telefonów VoIP Grandstream GXP16xx
Grandstream Networks GXP1628 <=1.0.4.130 is vulnerable to Incorrect Access Control. The device is configured w...
Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command executio...
Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command executio...