CVE-2018-17564: Grandstream GXP1610 Firmware
Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.
A Malformed Input String to /cgi-bin/delete_CA on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to delete configuration parameters and gain admin access to the device.
Affected products
- Grandstream GXP1610 Firmware: version 1.0.4.128 only
- Grandstream GXP1615 Firmware: version 1.0.4.128 only
- Grandstream GXP1620 Firmware: version 1.0.4.128 only
- Grandstream GXP1625 Firmware: version 1.0.4.128 only
- Grandstream GXP1628 Firmware: version 1.0.4.128 only
- Grandstream GXP1630 Firmware: version 1.0.4.128 only
Published 2019-04-01. Last modified 2026-06-17.