Vulnerabilities > Grandstream > Wave > High

DATE CVE VULNERABILITY TITLE RISK
2017-04-21 CVE-2016-1520 7PK - Security Features vulnerability in Grandstream Wave 1.0.1.26
The Grandstream Wave app 1.0.1.26 and earlier for Android does not use HTTPS when retrieving update information, which might allow man-in-the-middle attackers to execute arbitrary code via a crafted application.
local
low complexity
grandstream CWE-254
7.8
2017-04-21 CVE-2016-1518 Improper Access Control vulnerability in Grandstream Wave 1.0.1.26
The auto-provisioning mechanism in the Grandstream Wave app 1.0.1.26 and earlier for Android and Grandstream Video IP phones allows man-in-the-middle attackers to spoof provisioning data and consequently modify device functionality, obtain sensitive information from system logs, and have unspecified other impact by leveraging failure to use an HTTPS session for downloading configuration files from http://fm.grandstream.com/gs/.
network
high complexity
grandstream CWE-284
8.1