First published: Mon Mar 29 2021(Updated: )
Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allows Command Injection as root in its administrative web interface.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Grandstream Grp2612 Firmware | =1.0.3.6 | |
Grandstream Grp2612 | ||
Grandstream Grp2612p Firmware | =1.0.3.6 | |
Grandstream Grp2612p | ||
Grandstream Grp2612w Firmware | =1.0.3.6 | |
Grandstream Grp2612w | ||
Grandstream Grp2613 Firmware | =1.0.3.6 | |
Grandstream Grp2613 | ||
Grandstream Grp2614 Firmware | =1.0.3.6 | |
Grandstream Grp2614 | ||
Grandstream Grp2615 Firmware | =1.0.3.6 | |
Grandstream Grp2615 | ||
Grandstream Grp2616 Firmware | =1.0.3.6 | |
Grandstream Grp2616 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-25217 is a vulnerability found in the Grandstream GRP261x VoIP phone's administrative web interface.
CVE-2020-25217 has a severity level of 7.2 (critical).
CVE-2020-25217 allows command injection as root in the administrative web interface of the Grandstream GRP261x VoIP phone.
Yes, Grandstream GRP261x with firmware version 1.0.3.6 is vulnerable to CVE-2020-25217.
To fix CVE-2020-25217, update the firmware of the Grandstream GRP261x VoIP phone to a version that is not affected.