CVE-2020-25218

Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allow Authentication Bypass in its administrative web interface.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 57%
VendorProductVersion
grandstreamgrp2612_firmware
1.0.3.6
grandstreamgrp2612p_firmware
1.0.3.6
grandstreamgrp2612w_firmware
1.0.3.6
grandstreamgrp2613_firmware
1.0.3.6
grandstreamgrp2614_firmware
1.0.3.6
grandstreamgrp2615_firmware
1.0.3.6
grandstreamgrp2616_firmware
1.0.3.6
𝑥
= Vulnerable software versions