CVE-2020-25217: Grandstream GRP2612 Firmware

High severity, CVSS 7.2. EPSS: 2.4% chance of exploitation in the next 30 days.

Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allows Command Injection as root in its administrative web interface.

Affected products

Published 2021-03-29. Last modified 2026-06-17.