logo

Critical Grandstream VoIP Bug Highlights SMB Security Blind Spot

ID: de3f44e9-c18a-5f44-8fd7-f2e2c217c3c7

STIX ID: report--de3f44e9-c18a-5f44-8fd7-f2e2c217c3c7

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2026-02-18

Date Updated: 2026-04-21

Author: Jai Vijayan

...
...

A critical unauthenticated stack buffer overflow (CVE-2026-2329, CVSS 9.3) in Grandstream GXP1600 VoIP phones allows remote code execution with root privileges, enabling attackers to extract credentials, intercept SIP calls, commit toll fraud, and pivot within networks; Rapid7 published a Metasploit exploit and Grandstream released a patch—organizations are advised to update firmware, segment VoIP infrastructure, and harden SIP configurations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.