CVE-2025-28170: Grandstream GXP1628 Firmware

High severity, CVSS 7.6. EPSS: 0.3% chance of exploitation in the next 30 days.

Grandstream Networks GXP1628 <=1.0.4.130 is vulnerable to Incorrect Access Control. The device is configured with directory listing enabled, allowing unauthorized access to sensitive directories and files.

Affected products

  • Grandstream GXP1628 Firmware: up to and including 1.0.4.130

Published 2025-07-29. Last modified 2026-07-05.