logo

How to find Grandstream VoIP phones on your network

ID: ace736f0-2500-51df-85f8-69ae4130c2c6

STIX ID: report--ace736f0-2500-51df-85f8-69ae4130c2c6

Feed Name: runZero Blog

Threat Score
75/100

Date Published: 2026-02-20

Date Updated: 2026-04-29

Author: Matthew Kienow

...
...

Rapid7 disclosed a critical stack-based buffer overflow (CVE-2026-2329, CVSS 9.3) in Grandstream GXP1600-series VoIP phones' /cgi-bin/api.values.get HTTP API that allows unauthenticated remote code execution as root on affected devices (GXP1610, GXP1615, GXP1620, GXP1625, GXP1628, GXP1630) running firmware prior to 1.0.7.81; users are advised to upgrade to 1.0.7.81 or later and can use the provided runZero query to find potentially impacted assets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.