CVE-2019-10657: OS Command Injection
Grandstream GWN7000 before 1.0.6.32 and GWN7610 before 1.0.8.18 devices allow remote authenticated users to discover passwords via a /ubus/uci.apply config request.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability CVE-2019-10657?
The vulnerability CVE-2019-10657 is a security flaw in Grandstream GWN7000 and GWN7610 devices that allows remote authenticated users to discover passwords via a /ubus/uci.apply config request.
What is the severity of CVE-2019-10657?
The severity of CVE-2019-10657 is medium, with a severity value of 6.5.
Which software versions are affected by CVE-2019-10657?
Grandstream GWN7000 firmware versions up to exclusive 1.0.6.32 and GWN7610 firmware versions up to exclusive 1.0.8.18 are affected by CVE-2019-10657.
How can remote authenticated users exploit CVE-2019-10657?
Remote authenticated users can exploit CVE-2019-10657 by making a config request to /ubus/uci.apply to discover passwords.
Are Grandstream GWN7000 and GWN7610 devices vulnerable to CVE-2019-10657?
Yes, Grandstream GWN7000 and GWN7610 devices are vulnerable to CVE-2019-10657 if they are running firmware versions up to exclusive 1.0.6.32 and 1.0.8.18, respectively.