PT-2020-18660 · Grandstream · Grandstream Gxp1600

Published

2020-04-14

·

Updated

2020-04-18

·

CVE-2020-5738

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Grandstream GXP1600 series firmware versions 1.0.4.152 and below
Description The issue allows for authenticated remote command execution when an attacker uploads a specially crafted tar file to the HTTP /cgi-bin/upload vpntar interface.
Recommendations For Grandstream GXP1600 series firmware versions 1.0.4.152 and below, update to a version above 1.0.4.152 to resolve the issue. As a temporary workaround, consider restricting access to the HTTP /cgi-bin/upload vpntar interface until a patch is available.

Exploit

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-5738

Affected Products

Grandstream Gxp1600