Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

Lorde’s Gov Ball 2026 setlist features new songs and “Girl, So Confusing”

Black Crowes’ Chris Robinson makes comments on stage

Top 10 Pop, Rock, and Country Concerts of the Summer – Plus Jazz and Classical

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » Grandstream GXP1600 VoIP phone exposed to unauthenticated remote code execution
Celebrities

Grandstream GXP1600 VoIP phone exposed to unauthenticated remote code execution

By February 18, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ravi LakshmananFebruary 18, 2026Network Security/Enterprise Security

Cybersecurity researchers have revealed a critical security flaw in Grandstream GXP1600 series VoIP phones that could allow attackers to seize control of susceptible devices.

This vulnerability is tracked as CVE-2026-2329 and has a CVSS score of 9.3 out of a maximum of 10.0. This is described as a case of an unauthenticated stack-based buffer overflow that could lead to remote code execution.

“CVE-2026-2329 could allow a remote attacker to perform unauthenticated remote code execution (RCE) with root privileges on a target device,” said Rapid7 researcher Stephen Fewer, who discovered and reported the bug on January 6, 2026.

According to the cybersecurity firm, the issue is caused by the device’s web-based API service (‘/cgi-bin/api.values.get’), which can be accessed with default settings without requiring authentication.

This endpoint is designed to fetch one or more configuration values ​​from the phone, such as firmware version number and model, through a colon-separated string in the “request” parameter (for example, “request=68:phone_model”). This configuration value is then parsed to extract each identifier and add it to a 64-byte buffer on the stack.

“When appending another character to a small 64-byte buffer, no length check is performed to ensure that no more than 63 characters (plus the added null terminator) are written to this buffer,” Fewer explained. “Thus, an attacker-controlled ‘request’ parameter could write beyond the bounds of a small 64-byte buffer on the stack, potentially overflowing into adjacent stack memory. ”

This means that malicious colon-separated “request” parameters sent to the “/cgi-bin/api.values.get” endpoint as part of an HTTP request can be used to cause a stack-based buffer overflow, which allows a threat actor to corrupt the contents of the stack and ultimately execute remote code on the underlying operating system.

This vulnerability affects GXP1610, GXP1615, GXP1620, GXP1625, GXP1628, and GXP1630 models. This issue was addressed as part of a firmware update (version 1.0.7.81) released late last month.

A Metasploit exploit module developed by Rapid7 has demonstrated that this vulnerability can be exploited to gain root privileges on a vulnerable device and chained with a post-exploitation component to extract credentials stored on a compromised device.

Additionally, armed with remote code execution capabilities, reconfiguring a target device to use a malicious Session Initiation Protocol (SIP) proxy effectively allows an attacker to intercept calls to and from the device or eavesdrop on VoIP conversations. A SIP proxy is an intermediary server in a VoIP network for establishing and managing audio/video calls between endpoints.

“This is not a one-click exploit with fireworks and victory banners,” said Rapid7’s Douglas McKee. “However, the underlying vulnerabilities lower that barrier and should cause concern for anyone operating these devices in exposed or poorly segmented environments.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleThe largest trees in the Peruvian Amazon store the most carbon and also face the biggest threats from humans
Next Article Citizen Lab finds Cellebrite tool used on mobile phone of Kenyan activist in police custody

Related Posts

Princess Charlene of Monaco is enthusiastic about Monaco F1 Grand Prix

June 5, 2026

Queen Camilla wears Queen Elizabeth’s Diamond Star Brooch

June 5, 2026

Emily Blunt wears custom Stella McCartney to Disclosure Day in London

June 5, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Lorde’s Gov Ball 2026 setlist features new songs and “Girl, So Confusing”

Black Crowes’ Chris Robinson makes comments on stage

Top 10 Pop, Rock, and Country Concerts of the Summer – Plus Jazz and Classical

Italy’s 2026 Nameless Festival scales up without losing its soul

Trending Posts

Lorde’s Gov Ball 2026 setlist features new songs and “Girl, So Confusing”

June 6, 2026

Black Crowes’ Chris Robinson makes comments on stage

June 6, 2026

Italy’s 2026 Nameless Festival scales up without losing its soul

June 5, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.