CVE List


Critical 7.5

Grandstream HT800 series firmware version and below is vulnerable to a denial of service attack against the TR-069 service. An unauthenticated remote attacker can stop the service due to a NULL pointer dereference in the TR-069 service. This condition is triggered due to mishandling of the HTTP Authentication field.

Published July 29, 2020.

Affected software

Grandstream Ht802 Firmware

Grandstream Ht813 Firmware

Grandstream Ht801 Firmware

Grandstream Ht818 Firmware

Grandstream Ht814 Firmware

Grandstream Ht812 Firmware

Reference links

Sign Up for Alerts