CVE-2019-10655: Buffer Overflow

Published Mar 30, 2019
·
Updated

Grandstream GAC2500 1.0.3.35, GXP2200 1.0.3.27, GVC3202 1.0.3.51, GXV3275 before 1.0.3.219 Beta, and GXV3240 before 1.0.3.219 Beta devices allow unauthenticated remote code execution via shell metacharacters in a /manager?action=getlogcat priority field, in conjunction with a buffer overflow (via the phonecookie cookie) to overwrite a data structure and consequently bypass authentication. This can be exploited remotely or via CSRF because the cookie can be placed in an Accept HTTP header in an XMLHttpRequest call to lighttpd.

Affected Software

10 affected components
Grandstream Gac2500 Firmware<=1.0.3.35
Grandstream GAC2500
Grandstream Gvc3202 Firmware<1.0.3.51
Grandstream GVC3202
Grandstream Gxv3275 Firmware<1.0.3.219
Grandstream GXV3275
Grandstream Gxv3240 Firmware<1.0.3.219
Grandstream GXV3240
Grandstream Gxp2200 Firmware<=1.0.3.27
Grandstream GXP2200

Event History

Mar 30, 2019
CVE Published
via MITRE·04:42 PM
Data Sourced
via MITRE·04:42 PM
Description

Frequently Asked Questions

1

What is the vulnerability ID for this vulnerability?

The vulnerability ID for this vulnerability is CVE-2019-10655.

2

What is the severity of CVE-2019-10655?

CVE-2019-10655 has a severity rating of 9.8 (critical).

3

Which devices are affected by CVE-2019-10655?

Grandstream GAC2500 1.0.3.35, GXP2200 1.0.3.27, GVC3202 1.0.3.51, GXV3275 before 1.0.3.219 Beta, and GXV3240 before 1.0.3.219 Beta are affected by CVE-2019-10655.

4

How does the vulnerability CVE-2019-10655 allow remote code execution?

CVE-2019-10655 allows unauthenticated remote code execution via shell metacharacters in a /manager?action=getlogcat priority field, in conjunction with a buffer overflow.

5

Are there any available fixes for CVE-2019-10655?

There are currently no publicly available fixes for CVE-2019-10655.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203