Vulnerabilities > Grandstream > Gac2500 Firmware

DATE CVE VULNERABILITY TITLE RISK
2019-03-30 CVE-2019-10655 OS Command Injection vulnerability in Grandstream products
Grandstream GAC2500 1.0.3.35, GXP2200 1.0.3.27, GVC3202 1.0.3.51, GXV3275 before 1.0.3.219 Beta, and GXV3240 before 1.0.3.219 Beta devices allow unauthenticated remote code execution via shell metacharacters in a /manager?action=getlogcat priority field, in conjunction with a buffer overflow (via the phonecookie cookie) to overwrite a data structure and consequently bypass authentication.
network
low complexity
grandstream CWE-78
7.5