CVE-2025-28171: Grandstream UCM6510 Firmware

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

An issue in Grandstream UCM6510 v.1.0.20.52 and before allows a remote attacker to obtain sensitive information via the Login function at /cgi and /webrtccgi.

Affected products

  • Grandstream UCM6510 Firmware: up to and including 1.0.20.52

Published 2025-07-29. Last modified 2026-07-05.