First published: Thu Oct 28 2021(Updated: )
An issue was discovered on the Grandstream HT801 Analog Telephone Adaptor before 1.0.29.8. From the limited configuration shell, it is possible to set the malicious gdb_debug_server variable. As a result, after a reboot, the device downloads and executes malicious scripts from an attacker-defined host.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Grandstream Ht801 Firmware | <1.0.29.8 | |
Grandstream HT801 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-37915 is a vulnerability discovered on the Grandstream HT801 Analog Telephone Adaptor before version 1.0.29.8.
CVE-2021-37915 has a severity rating of 8.8, which is considered critical.
CVE-2021-37915 allows an attacker to set a malicious gdb_debug_server variable on the Grandstream HT801, which can result in the device downloading and executing malicious scripts from an attacker-defined host.
To fix the CVE-2021-37915 vulnerability, it is recommended to update the Grandstream HT801 Analog Telephone Adaptor firmware to version 1.0.29.8 or later.
You can find more information about CVE-2021-37915 on the Grandstream website and the provided references.