Permissions, Privileges, and Access Controls in Grandstream Networks, Inc. products - CVE-2018-17564
Published: November 20, 2019
GXP1610
GXP1615
GXP1620
GXP1625
GXP1628
GXP1630
Grandstream Basic IP Phones firmware
Grandstream Networks, Inc.
Description
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to the "/app/war/cgi-bin/delete_CA" haserl script does not require authentication and permits to delete a previously uploaded CA certificate. A remote attacker can delete configuration parameters and gain admin access to the device.