Critical Grandstream VoIP Bug Highlights SMB Security Blind Spot
ID: de3f44e9-c18a-5f44-8fd7-f2e2c217c3c7
STIX ID: report--de3f44e9-c18a-5f44-8fd7-f2e2c217c3c7
Feed Name: Dark Reading
Threat Score
A critical unauthenticated stack buffer overflow (CVE-2026-2329, CVSS 9.3) in Grandstream GXP1600 VoIP phones allows remote code execution with root privileges, enabling attackers to extract credentials, intercept SIP calls, commit toll fraud, and pivot within networks; Rapid7 published a Metasploit exploit and Grandstream released a patch—organizations are advised to update firmware, segment VoIP infrastructure, and harden SIP configurations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
