CVE-2026-2329
Received
Received - Intake
Stack-Based Buffer Overflow in GXP Series HTTP API Enables Root RCE
Publication date: 2026-02-18
Last updated on: 2026-02-20
Assigner: Rapid7, Inc.
Description
Description
An unauthenticated stack-based buffer overflow vulnerability exists in the HTTP API endpoint /cgi-bin/api.values.get. A remote attacker can leverage this vulnerability to achieve unauthenticated remote code execution (RCE) with root privileges on a target device. The vulnerability affects all six device models in the series: GXP1610, GXP1615, GXP1620, GXP1625, GXP1628, and GXP1630.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| grandstream | gxp1610_firmware | to 1.0.7.81 (exc) |
| grandstream | gxp1615_firmware | to 1.0.7.81 (exc) |
| grandstream | gxp1620_firmware | to 1.0.7.81 (exc) |
| grandstream | gxp1625_firmware | to 1.0.7.81 (exc) |
| grandstream | gxp1628_firmware | to 1.0.7.81 (exc) |
| grandstream | gxp1630_firmware | to 1.0.7.81 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-121 | A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function). |