CVE-2018-17565: Grandstream GXP1610 Firmware
Critical severity, CVSS 9.8. EPSS: 1.9% chance of exploitation in the next 30 days.
Shell Metacharacter Injection in the SSH configuration interface on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to execute arbitrary system commands and gain a root shell.
Affected products
- Grandstream GXP1610 Firmware: version 1.0.4.128 only
- Grandstream GXP1615 Firmware: version 1.0.4.128 only
- Grandstream GXP1620 Firmware: version 1.0.4.128 only
- Grandstream GXP1625 Firmware: version 1.0.4.128 only
- Grandstream GXP1628 Firmware: version 1.0.4.128 only
- Grandstream GXP1630 Firmware: version 1.0.4.128 only
Published 2019-04-01. Last modified 2026-06-17.