9
CVSSv2

CVE-2021-37915

Published: 28/10/2021 Updated: 02/11/2021
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

An issue exists on the Grandstream HT801 Analog Telephone Adaptor prior to 1.0.29.8. From the limited configuration shell, it is possible to set the malicious gdb_debug_server variable. As a result, after a reboot, the device downloads and executes malicious scripts from an attacker-defined host.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

grandstream ht801_firmware

Github Repositories

Exploits for the CVE-2021-37748 Full writeup: wwwsecforcecom/blog/exploiting-grandstream-ht801-ata-cve-2021-37748-cve-2021-37915/