CVE-2025-28171: Medium severity Grandstream UCM6510 vulnerability
Published Jul 29, 2025
·Updated
An issue in Grandstream UCM6510 v.1.0.20.52 and before allows a remote attacker to obtain sensitive information via the Login function at /cgi and /webrtccgi.
Affected Software
3 affected components
Grandstream UCM6510<1.0.20.52
All of the following
Grandstream Ucm6510 Firmware<=1.0.20.52
Grandstream UCM6510
Event History
Jul 29, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-28171?
CVE-2025-28171 has been rated as a medium severity vulnerability due to the potential for sensitive information exposure.
2
How do I fix CVE-2025-28171?
To fix CVE-2025-28171, upgrade the Grandstream UCM6510 to a version later than 1.0.20.52.
3
What type of information can be leaked by CVE-2025-28171?
CVE-2025-28171 allows a remote attacker to obtain sensitive information through the affected Login function.
4
Which products are affected by CVE-2025-28171?
CVE-2025-28171 affects the Grandstream UCM6510 running version 1.0.20.52 and prior.
5
Is CVE-2025-28171 remotely exploitable?
Yes, CVE-2025-28171 can be exploited remotely without requiring physical access to the device.