Vulnerabilities > CVE-2016-1520 - 7PK - Security Features vulnerability in Grandstream Wave

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL

Summary

The Grandstream Wave app 1.0.1.26 and earlier for Android does not use HTTPS when retrieving update information, which might allow man-in-the-middle attackers to execute arbitrary code via a crafted application.

Vulnerable Configurations

Part Description Count
Application
Grandstream
1

Common Weakness Enumeration (CWE)

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/136291/grandstream-redir.txt
idPACKETSTORM:136291
last seen2016-12-05
published2016-03-18
reporterGeorg Lukas
sourcehttps://packetstormsecurity.com/files/136291/Grandstream-Wave-1.0.1.26-Update-Redirection.html
titleGrandstream Wave 1.0.1.26 Update Redirection