logo

Grandstream GXP1600 VoIP Phones Exposed to Unauthenticated Remote Code Execution

ID: 899a8f66-0588-5afa-be3c-8add9c0c41ce

STIX ID: report--899a8f66-0588-5afa-be3c-8add9c0c41ce

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-02-18

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Critical unauthenticated stack-based buffer overflow (CVE-2026-2329, CVSS 9.3) in Grandstream GXP1600-series VoIP phones allows remote code execution as root via the web API endpoint "/cgi-bin/api.values.get" by sending a malicious colon-delimited "request" parameter; Rapid7 published a Metasploit module demonstrating exploitation and Grandstream released firmware 1.0.7.81 to address the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.