CVE-2023-50015: Grandstream GXP1400 Firmware

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

An issue was discovered in Grandstream GXP14XX 1.0.8.9 and GXP16XX 1.0.7.13, allows remote attackers to escalate privileges via incorrect access control using an end-user session-identity token.

Affected products

  • Grandstream GXP1400 Firmware: up to and including 1.0.8.9
  • Grandstream GXP1405 Firmware: up to and including 1.0.8.9
  • Grandstream GXP1610 Firmware: up to and including 1.0.7.13
  • Grandstream GXP1615 Firmware: up to and including 1.0.7.13
  • Grandstream GXP1620 Firmware: up to and including 1.0.7.13
  • Grandstream GXP1625 Firmware: up to and including 1.0.7.13
  • Grandstream GXP1628 Firmware: up to and including 1.0.7.13
  • Grandstream GXP1630 Firmware: up to and including 1.0.7.13

Published 2024-03-09. Last modified 2026-06-17.