Vulnerabilities > Grandstream > Gxp1620 Firmware > Critical

DATE CVE VULNERABILITY TITLE RISK
2019-04-01 CVE-2018-17564 Unspecified vulnerability in Grandstream products
A Malformed Input String to /cgi-bin/delete_CA on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to delete configuration parameters and gain admin access to the device.
network
low complexity
grandstream
critical
9.8
2019-04-01 CVE-2018-17565 OS Command Injection vulnerability in Grandstream products
Shell Metacharacter Injection in the SSH configuration interface on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to execute arbitrary system commands and gain a root shell.
network
low complexity
grandstream CWE-78
critical
9.8