← Back to CVEs
CVE-2018-17565
N/ADescription
Shell Metacharacter Injection in the SSH configuration interface on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to execute arbitrary system commands and gain a root shell.
CVE Details
CVSS v3.1 ScoreN/A
Published4/1/2019
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0
Affected Products
grandstream:gxp1610grandstream:gxp1610_firmwaregrandstream:gxp1615grandstream:gxp1615_firmwaregrandstream:gxp1620grandstream:gxp1620_firmwaregrandstream:gxp1625grandstream:gxp1625_firmwaregrandstream:gxp1628grandstream:gxp1628_firmwaregrandstream:gxp1630grandstream:gxp1630_firmware
Weaknesses (CWE)
CWE-78
References
http://grandstream.com/support/firmware(cve@mitre.org)
http://grandstream.com/support/firmware(af854a3a-2127-422b-91ae-364da2661108)
https://iridiumxor.wordpress.com/2019/01/03/three-simple-cves-for-a-good-voip-phone/(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.