7.5
CVSSv2

CVE-2015-2866

Published: 08/07/2015 Updated: 03/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability on the Grandstream GXV3611_HD camera with firmware prior to 1.0.3.9 beta allows remote malicious users to execute arbitrary SQL commands by attempting to establish a TELNET session with a crafted username.

Vulnerable Product Search on Vulmon Subscribe to Product

grandstream gxv3611_hd_firmware

Exploits

# Exploit Title: Grandstream GXV3611_HD Telnet SQL Injection and backdoor command # Exploit Author: pizza1337 # Vendor Homepage: wwwgrandstreamcom/ # Version: GXV3611_HD Core 1036, 1043 # GXV3611IR_HD Core 1035 # Tested on: # -GXV3611_HD # Bootloader Version: 1000 # Core Version: 1043 # Base Version: 10443 # Firmwa ...