CVE-2026-93338: Grandstream GWN7660ELR < 1.0.27.6 Information Disclosure via SNMP Default Community String

Published Sep 18, 2026
·
Updated

Grandstream GWN7660ELR before firmware version 1.0.27.6 contains an information disclosure vulnerability that allows unauthenticated remote attackers to obtain sensitive system information by querying the SNMP v2c service configured with the default community string 'public'. Attackers can query standard MIBs over the SNMP port to retrieve operating system and kernel version, running process names and command-line arguments, network interface configuration, routing table entries, ARP table mappings, active TCP connection details, and file system paths, enabling detailed reconnaissance of the device and adjacent network infrastructure.

Affected Software

1 affected component
Grandstream GWN7660ELR<1.0.27.6

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Grandstream GWN7660ELR firmware to a version that resolves this vulnerability.

    Fixed in 1.0.27.6
  2. Configuration

    Ensure the SNMP v2c service is not configured with the default community string 'public' (replace it with a non-default value or otherwise remove the default community configuration).

    SNMP v2c on Grandstream GWN7660ELR default community string = public

Event History

Sep 18, 2026
CVE Published
via MITRE·04:21 PM
Data Sourced
via MITRE·04:21 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Grandstream GWN7660ELR devices running firmware earlier than 1.0.27.6 are exposed if their SNMP v2c service is configured with the default community string "public" and is reachable by an attacker.

2

What does an attacker need to exploit it?

An attacker needs only network access to the device's SNMP service. No authentication, privileges, or user interaction are required when the default "public" community string is accepted.

3

What information can be obtained?

Queries to standard MIBs can disclose operating system and kernel versions, process names and command-line arguments, interface and routing configuration, ARP mappings, active TCP connections, and file system paths. This information can support reconnaissance of the device and adjacent network infrastructure.

4

How can exposure be reduced before updating firmware?

Change the SNMP v2c community string from the default "public" value and restrict access to the SNMP service to trusted management networks. Firmware version 1.0.27.6 is the stated fixed version.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203