CVE-2018-17563: Grandstream GXP1610 Firmware
Medium severity, CVSS 5.3. EPSS: 0.7% chance of exploitation in the next 30 days.
A Malformed Input String to /cgi-bin/api-get_line_status on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to dump the device's configuration in cleartext.
Affected products
- Grandstream GXP1610 Firmware: version 1.0.4.128 only
- Grandstream GXP1615 Firmware: version 1.0.4.128 only
- Grandstream GXP1620 Firmware: version 1.0.4.128 only
- Grandstream GXP1625 Firmware: version 1.0.4.128 only
- Grandstream GXP1628 Firmware: version 1.0.4.128 only
- Grandstream GXP1630 Firmware: version 1.0.4.128 only
Published 2019-04-01. Last modified 2026-06-17.