OS Command Injection in Grandstream Networks, Inc. products - CVE-2018-17565
Published: November 20, 2019
Grandstream Basic IP Phones firmware
GXP1610
GXP1615
GXP1620
GXP1625
GXP1628
GXP1630
Grandstream Networks, Inc.
Description
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to Shell Metacharacter Injection in the SSH configuration interface. A remote unauthenticated attacker can execute arbitrary OS commands and gain a root shell on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.