First published: Sat Mar 30 2019(Updated: )
Grandstream GWN7000 before 1.0.6.32 and GWN7610 before 1.0.8.18 devices allow remote authenticated users to discover passwords via a /ubus/uci.apply config request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Grandstream Gwn7610 Firmware | <1.0.8.18 | |
Grandstream GWN7610 | ||
Grandstream GWN7000 firmware | <1.0.6.32 | |
Grandstream GWN7000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability CVE-2019-10657 is a security flaw in Grandstream GWN7000 and GWN7610 devices that allows remote authenticated users to discover passwords via a /ubus/uci.apply config request.
The severity of CVE-2019-10657 is medium, with a severity value of 6.5.
Grandstream GWN7000 firmware versions up to exclusive 1.0.6.32 and GWN7610 firmware versions up to exclusive 1.0.8.18 are affected by CVE-2019-10657.
Remote authenticated users can exploit CVE-2019-10657 by making a config request to /ubus/uci.apply to discover passwords.
Yes, Grandstream GWN7000 and GWN7610 devices are vulnerable to CVE-2019-10657 if they are running firmware versions up to exclusive 1.0.6.32 and 1.0.8.18, respectively.