CVE-2020-5738
14.04.2020, 14:15
Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker uploads a specially crafted tar file to the HTTP /cgi-bin/upload_vpntar interface.
Vendor | Product | Version |
---|---|---|
grandstream | gxp1610_firmware | 𝑥 ≤ 1.0.4.152 |
grandstream | gxp1615_firmware | 𝑥 ≤ 1.0.4.152 |
grandstream | gxp1620_firmware | 𝑥 ≤ 1.0.4.152 |
grandstream | gxp1625_firmware | 𝑥 ≤ 1.0.4.152 |
grandstream | gxp1628_firmware | 𝑥 ≤ 1.0.4.152 |
grandstream | gxp1630_firmware | 𝑥 ≤ 1.0.4.152 |
𝑥
= Vulnerable software versions