CVE-2025-28170: Grandstream GXP1628 Firmware
High severity, CVSS 7.6. EPSS: 0.3% chance of exploitation in the next 30 days.
Grandstream Networks GXP1628 <=1.0.4.130 is vulnerable to Incorrect Access Control. The device is configured with directory listing enabled, allowing unauthorized access to sensitive directories and files.
Affected products
- Grandstream GXP1628 Firmware: up to and including 1.0.4.130
Published 2025-07-29. Last modified 2026-07-05.