CVE-2019-10656: Grandstream GWN7000 Firmware

High severity, CVSS 8.8. EPSS: 3.9% chance of exploitation in the next 30 days.

Grandstream GWN7000 before 1.0.6.32 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filename in a /ubus/uci.apply update_nds_webroot_from_tmp API call.

Affected products

  • Grandstream GWN7000 Firmware: before 1.0.6.32 (fixed in 1.0.6.32)

Published 2019-03-30. Last modified 2026-06-17.