216.73.216.233

CVE-2026-2329

· Published 18/02/2026 15:18 · Modified 18/02/2026 17:51

Labels: CVE-2026-2329 2026-02-18CVE-2026-2329CWE-121[email protected]

Essential information

Published
18/02/2026 15:18
Modified
18/02/2026 17:51
Author
Creator
CVSS
9.3 CRITICAL (v3) 9.3 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

An unauthenticated stack-based buffer overflow vulnerability exists in the HTTP API endpoint /cgi-bin/api.values.get. A remote attacker can leverage this vulnerability to achieve unauthenticated remote code execution (RCE) with root privileges on a target device. The vulnerability affects all six device models in the series: GXP1610, GXP1615, GXP1620, GXP1625, GXP1628, and GXP1630.

NVD status

Status
Undergoing Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
grandstream / gxpb cpe:2.3:a:grandstream:gxpb:*-*-*-*-*-*:*
grandstream / gxpb cpe:2.3:a:grandstream:gxpb:*-*-*-*-*-*-:*

References