9
CVSSv2

CVE-2020-25217

Published: 29/03/2021 Updated: 05/10/2022
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allows Command Injection as root in its administrative web interface.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

grandstream grp2612_firmware 1.0.3.6

grandstream grp2612p_firmware 1.0.3.6

grandstream grp2612w_firmware 1.0.3.6

grandstream grp2613_firmware 1.0.3.6

grandstream grp2614_firmware 1.0.3.6

grandstream grp2615_firmware 1.0.3.6

grandstream grp2616_firmware 1.0.3.6