Vulnerabilities > CVE-2016-1520 - 7PK - Security Features vulnerability in Grandstream Wave 1.0.1.26

047910
CVSS 7.8 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
local
low complexity
grandstream
CWE-254

Summary

The Grandstream Wave app 1.0.1.26 and earlier for Android does not use HTTPS when retrieving update information, which might allow man-in-the-middle attackers to execute arbitrary code via a crafted application.

Vulnerable Configurations

Part Description Count
Application
Grandstream
1

Common Weakness Enumeration (CWE)

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/136291/grandstream-redir.txt
idPACKETSTORM:136291
last seen2016-12-05
published2016-03-18
reporterGeorg Lukas
sourcehttps://packetstormsecurity.com/files/136291/Grandstream-Wave-1.0.1.26-Update-Redirection.html
titleGrandstream Wave 1.0.1.26 Update Redirection