CVE-2019-10658: Grandstream GWN7610 Firmware
High severity, CVSS 8.8. EPSS: 2.6% chance of exploitation in the next 30 days.
Grandstream GWN7610 before 1.0.8.18 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filename in a /ubus/controller.icc.update_nds_webroot_from_tmp update_nds_webroot_from_tmp API call.
Affected products
- Grandstream GWN7610 Firmware: before 1.0.8.18 (fixed in 1.0.8.18)
Published 2019-03-30. Last modified 2026-06-17.