Jonás Ropero Castillo

#3749de 53,639
69.2CVSS total
Vulnerabilidades · 10
Média
6
Alta
4
PT-2013-4762
4.3
2013-10-01
Grandstream · Gxv3651Fhd · CVE-2013-3962
**Name of the Vulnerable Software and Affected Versions** Grandstream GXV3501 versions prior to 1.0.4.44 Grandstream GXV3504 versions prior to 1.0.4.44 Grandstream GXV3601 versions prior to 1.0.4.44 Grandstream GXV3601HD/LL versions prior to 1.0.4.44 Grandstream GXV3611HD/LL versions prior to 1.0.4.44 Grandstream GXV3615W/P versions prior to 1.0.4.44 Grandstream GXV3651FHD versions prior to 1.0.4.44 Grandstream GXV3662HD versions prior to 1.0.4.44 Grandstream GXV3615WP HD versions prior to 1.0.4.44 Grandstream GXV3500 versions prior to 1.0.4.44 **Description** A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML via the `PATH INFO`. This could potentially lead to unauthorized access or control of the affected devices. **Recommendations** For Grandstream GXV3501, update to firmware version 1.0.4.44 or later. For Grandstream GXV3504, update to firmware version 1.0.4.44 or later. For Grandstream GXV3601, update to firmware version 1.0.4.44 or later. For Grandstream GXV3601HD/LL, update to firmware version 1.0.4.44 or later. For Grandstream GXV3611HD/LL, update to firmware version 1.0.4.44 or later. For Grandstream GXV3615W/P, update to firmware version 1.0.4.44 or later. For Grandstream GXV3651FHD, update to firmware version 1.0.4.44 or later. For Grandstream GXV3662HD, update to firmware version 1.0.4.44 or later. For Grandstream GXV3615WP HD, update to firmware version 1.0.4.44 or later. For Grandstream GXV3500, update to firmware version 1.0.4.44 or later.
PT-2013-4763
6.8
2013-10-01
Grandstream · Grandstream Gxv3601 · CVE-2013-3963
**Name of the Vulnerable Software and Affected Versions** Grandstream GXV3501 versions (affected versions not specified) Grandstream GXV3504 versions (affected versions not specified) Grandstream GXV3601 versions (affected versions not specified) Grandstream GXV3601HD/LL versions (affected versions not specified) Grandstream GXV3611HD/LL versions (affected versions not specified) Grandstream GXV3615W/P versions (affected versions not specified) Grandstream GXV3651FHD versions (affected versions not specified) Grandstream GXV3662HD versions (affected versions not specified) Grandstream GXV3615WP HD versions (affected versions not specified) Grandstream GXV3500 versions (affected versions not specified) **Description** A cross-site request forgery (CSRF) issue exists in the goform/usermanage endpoint of Grandstream camera models, allowing remote attackers to hijack the authentication of victims for requests that add users. **Recommendations** For Grandstream GXV3501, consider disabling the goform/usermanage endpoint until a patch is available. For Grandstream GXV3504, restrict access to the goform/usermanage endpoint to minimize the risk of exploitation. For Grandstream GXV3601, avoid using the goform/usermanage endpoint until the issue is resolved. For Grandstream GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P, GXV3651FHD, GXV3662HD, GXV3615WP HD, and GXV3500, at the moment, there is no information about a newer version that contains a fix for this issue.