Vulnerability Details CVE-2026-2329
An unauthenticated stack-based buffer overflow vulnerability exists in the HTTP API endpoint /cgi-bin/api.values.get. A remote attacker can leverage this vulnerability to achieve unauthenticated remote code execution (RCE) with root privileges on a target device. The vulnerability affects all six device models in the series: GXP1610, GXP1615, GXP1620, GXP1625, GXP1628, and GXP1630.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 25.7%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2026-2329
-
cpe:2.3:h:grandstream:gxp1610:-
-
cpe:2.3:h:grandstream:gxp1615:-
-
cpe:2.3:h:grandstream:gxp1620:-
-
cpe:2.3:h:grandstream:gxp1625:-
-
cpe:2.3:h:grandstream:gxp1628:-
-
cpe:2.3:h:grandstream:gxp1630:-
-
cpe:2.3:o:grandstream:gxp1610_firmware:1.0.4.100
-
cpe:2.3:o:grandstream:gxp1610_firmware:1.0.4.106
-
cpe:2.3:o:grandstream:gxp1610_firmware:1.0.4.128
-
cpe:2.3:o:grandstream:gxp1610_firmware:1.0.4.132
-
cpe:2.3:o:grandstream:gxp1610_firmware:1.0.4.140
-
cpe:2.3:o:grandstream:gxp1610_firmware:1.0.4.152
-
cpe:2.3:o:grandstream:gxp1610_firmware:1.0.4.82
-
cpe:2.3:o:grandstream:gxp1610_firmware:1.0.4.88
-
cpe:2.3:o:grandstream:gxp1610_firmware:1.0.5.3
-
cpe:2.3:o:grandstream:gxp1610_firmware:1.0.7.13
-
cpe:2.3:o:grandstream:gxp1610_firmware:1.0.7.18
-
cpe:2.3:o:grandstream:gxp1610_firmware:1.0.7.24
-
cpe:2.3:o:grandstream:gxp1610_firmware:1.0.7.27
-
cpe:2.3:o:grandstream:gxp1610_firmware:1.0.7.3
-
cpe:2.3:o:grandstream:gxp1610_firmware:1.0.7.33
-
cpe:2.3:o:grandstream:gxp1610_firmware:1.0.7.49
-
cpe:2.3:o:grandstream:gxp1610_firmware:1.0.7.50
-
cpe:2.3:o:grandstream:gxp1610_firmware:1.0.7.56
-
cpe:2.3:o:grandstream:gxp1610_firmware:1.0.7.6
-
cpe:2.3:o:grandstream:gxp1610_firmware:1.0.7.64
-
cpe:2.3:o:grandstream:gxp1610_firmware:1.0.7.67
-
cpe:2.3:o:grandstream:gxp1610_firmware:1.0.7.70
-
cpe:2.3:o:grandstream:gxp1610_firmware:1.0.7.74
-
cpe:2.3:o:grandstream:gxp1610_firmware:1.0.7.79
-
cpe:2.3:o:grandstream:gxp1610_firmware:1.0.7.80
-
cpe:2.3:o:grandstream:gxp1615_firmware:1.0.4.100
-
cpe:2.3:o:grandstream:gxp1615_firmware:1.0.4.106
-
cpe:2.3:o:grandstream:gxp1615_firmware:1.0.4.128
-
cpe:2.3:o:grandstream:gxp1615_firmware:1.0.4.132
-
cpe:2.3:o:grandstream:gxp1615_firmware:1.0.4.140
-
cpe:2.3:o:grandstream:gxp1615_firmware:1.0.4.152
-
cpe:2.3:o:grandstream:gxp1615_firmware:1.0.4.82
-
cpe:2.3:o:grandstream:gxp1615_firmware:1.0.4.88
-
cpe:2.3:o:grandstream:gxp1615_firmware:1.0.5.3
-
cpe:2.3:o:grandstream:gxp1615_firmware:1.0.7.13
-
cpe:2.3:o:grandstream:gxp1615_firmware:1.0.7.18
-
cpe:2.3:o:grandstream:gxp1615_firmware:1.0.7.24
-
cpe:2.3:o:grandstream:gxp1615_firmware:1.0.7.27
-
cpe:2.3:o:grandstream:gxp1615_firmware:1.0.7.3
-
cpe:2.3:o:grandstream:gxp1615_firmware:1.0.7.33
-
cpe:2.3:o:grandstream:gxp1615_firmware:1.0.7.49
-
cpe:2.3:o:grandstream:gxp1615_firmware:1.0.7.50
-
cpe:2.3:o:grandstream:gxp1615_firmware:1.0.7.56
-
cpe:2.3:o:grandstream:gxp1615_firmware:1.0.7.6
-
cpe:2.3:o:grandstream:gxp1615_firmware:1.0.7.64
-
cpe:2.3:o:grandstream:gxp1615_firmware:1.0.7.67
-
cpe:2.3:o:grandstream:gxp1615_firmware:1.0.7.70
-
cpe:2.3:o:grandstream:gxp1615_firmware:1.0.7.74
-
cpe:2.3:o:grandstream:gxp1615_firmware:1.0.7.79
-
cpe:2.3:o:grandstream:gxp1615_firmware:1.0.7.80
-
cpe:2.3:o:grandstream:gxp1620_firmware:1.0.4.100
-
cpe:2.3:o:grandstream:gxp1620_firmware:1.0.4.106
-
cpe:2.3:o:grandstream:gxp1620_firmware:1.0.4.128
-
cpe:2.3:o:grandstream:gxp1620_firmware:1.0.4.132
-
cpe:2.3:o:grandstream:gxp1620_firmware:1.0.4.140
-
cpe:2.3:o:grandstream:gxp1620_firmware:1.0.4.152
-
cpe:2.3:o:grandstream:gxp1620_firmware:1.0.4.82
-
cpe:2.3:o:grandstream:gxp1620_firmware:1.0.4.88
-
cpe:2.3:o:grandstream:gxp1620_firmware:1.0.5.3
-
cpe:2.3:o:grandstream:gxp1620_firmware:1.0.7.13
-
cpe:2.3:o:grandstream:gxp1620_firmware:1.0.7.18
-
cpe:2.3:o:grandstream:gxp1620_firmware:1.0.7.24
-
cpe:2.3:o:grandstream:gxp1620_firmware:1.0.7.27
-
cpe:2.3:o:grandstream:gxp1620_firmware:1.0.7.3
-
cpe:2.3:o:grandstream:gxp1620_firmware:1.0.7.33
-
cpe:2.3:o:grandstream:gxp1620_firmware:1.0.7.49
-
cpe:2.3:o:grandstream:gxp1620_firmware:1.0.7.50
-
cpe:2.3:o:grandstream:gxp1620_firmware:1.0.7.56
-
cpe:2.3:o:grandstream:gxp1620_firmware:1.0.7.6
-
cpe:2.3:o:grandstream:gxp1620_firmware:1.0.7.64
-
cpe:2.3:o:grandstream:gxp1620_firmware:1.0.7.67
-
cpe:2.3:o:grandstream:gxp1620_firmware:1.0.7.70
-
cpe:2.3:o:grandstream:gxp1620_firmware:1.0.7.74
-
cpe:2.3:o:grandstream:gxp1620_firmware:1.0.7.79
-
cpe:2.3:o:grandstream:gxp1620_firmware:1.0.7.80
-
cpe:2.3:o:grandstream:gxp1625_firmware:1.0.4.100
-
cpe:2.3:o:grandstream:gxp1625_firmware:1.0.4.106
-
cpe:2.3:o:grandstream:gxp1625_firmware:1.0.4.128
-
cpe:2.3:o:grandstream:gxp1625_firmware:1.0.4.132
-
cpe:2.3:o:grandstream:gxp1625_firmware:1.0.4.140
-
cpe:2.3:o:grandstream:gxp1625_firmware:1.0.4.152
-
cpe:2.3:o:grandstream:gxp1625_firmware:1.0.4.82
-
cpe:2.3:o:grandstream:gxp1625_firmware:1.0.4.88
-
cpe:2.3:o:grandstream:gxp1625_firmware:1.0.5.3
-
cpe:2.3:o:grandstream:gxp1625_firmware:1.0.7.13
-
cpe:2.3:o:grandstream:gxp1625_firmware:1.0.7.18
-
cpe:2.3:o:grandstream:gxp1625_firmware:1.0.7.24
-
cpe:2.3:o:grandstream:gxp1625_firmware:1.0.7.27
-
cpe:2.3:o:grandstream:gxp1625_firmware:1.0.7.3
-
cpe:2.3:o:grandstream:gxp1625_firmware:1.0.7.33
-
cpe:2.3:o:grandstream:gxp1625_firmware:1.0.7.49
-
cpe:2.3:o:grandstream:gxp1625_firmware:1.0.7.50
-
cpe:2.3:o:grandstream:gxp1625_firmware:1.0.7.56
-
cpe:2.3:o:grandstream:gxp1625_firmware:1.0.7.6
-
cpe:2.3:o:grandstream:gxp1625_firmware:1.0.7.64
-
cpe:2.3:o:grandstream:gxp1625_firmware:1.0.7.67
-
cpe:2.3:o:grandstream:gxp1625_firmware:1.0.7.70
-
cpe:2.3:o:grandstream:gxp1625_firmware:1.0.7.74
-
cpe:2.3:o:grandstream:gxp1625_firmware:1.0.7.79
-
cpe:2.3:o:grandstream:gxp1625_firmware:1.0.7.80
-
cpe:2.3:o:grandstream:gxp1628_firmware:1.0.4.100
-
cpe:2.3:o:grandstream:gxp1628_firmware:1.0.4.106
-
cpe:2.3:o:grandstream:gxp1628_firmware:1.0.4.128
-
cpe:2.3:o:grandstream:gxp1628_firmware:1.0.4.130
-
cpe:2.3:o:grandstream:gxp1628_firmware:1.0.4.132
-
cpe:2.3:o:grandstream:gxp1628_firmware:1.0.4.140
-
cpe:2.3:o:grandstream:gxp1628_firmware:1.0.4.152
-
cpe:2.3:o:grandstream:gxp1628_firmware:1.0.4.82
-
cpe:2.3:o:grandstream:gxp1628_firmware:1.0.4.88
-
cpe:2.3:o:grandstream:gxp1628_firmware:1.0.5.3
-
cpe:2.3:o:grandstream:gxp1628_firmware:1.0.7.13
-
cpe:2.3:o:grandstream:gxp1628_firmware:1.0.7.18
-
cpe:2.3:o:grandstream:gxp1628_firmware:1.0.7.24
-
cpe:2.3:o:grandstream:gxp1628_firmware:1.0.7.27
-
cpe:2.3:o:grandstream:gxp1628_firmware:1.0.7.3
-
cpe:2.3:o:grandstream:gxp1628_firmware:1.0.7.33
-
cpe:2.3:o:grandstream:gxp1628_firmware:1.0.7.49
-
cpe:2.3:o:grandstream:gxp1628_firmware:1.0.7.50
-
cpe:2.3:o:grandstream:gxp1628_firmware:1.0.7.56
-
cpe:2.3:o:grandstream:gxp1628_firmware:1.0.7.6
-
cpe:2.3:o:grandstream:gxp1628_firmware:1.0.7.64
-
cpe:2.3:o:grandstream:gxp1628_firmware:1.0.7.67
-
cpe:2.3:o:grandstream:gxp1628_firmware:1.0.7.70
-
cpe:2.3:o:grandstream:gxp1628_firmware:1.0.7.74
-
cpe:2.3:o:grandstream:gxp1628_firmware:1.0.7.79
-
cpe:2.3:o:grandstream:gxp1628_firmware:1.0.7.80
-
cpe:2.3:o:grandstream:gxp1630_firmware:1.0.4.100
-
cpe:2.3:o:grandstream:gxp1630_firmware:1.0.4.106
-
cpe:2.3:o:grandstream:gxp1630_firmware:1.0.4.128
-
cpe:2.3:o:grandstream:gxp1630_firmware:1.0.4.132
-
cpe:2.3:o:grandstream:gxp1630_firmware:1.0.4.140
-
cpe:2.3:o:grandstream:gxp1630_firmware:1.0.4.152
-
cpe:2.3:o:grandstream:gxp1630_firmware:1.0.4.82
-
cpe:2.3:o:grandstream:gxp1630_firmware:1.0.4.88
-
cpe:2.3:o:grandstream:gxp1630_firmware:1.0.5.3
-
cpe:2.3:o:grandstream:gxp1630_firmware:1.0.7.13
-
cpe:2.3:o:grandstream:gxp1630_firmware:1.0.7.18
-
cpe:2.3:o:grandstream:gxp1630_firmware:1.0.7.24
-
cpe:2.3:o:grandstream:gxp1630_firmware:1.0.7.27
-
cpe:2.3:o:grandstream:gxp1630_firmware:1.0.7.3
-
cpe:2.3:o:grandstream:gxp1630_firmware:1.0.7.33
-
cpe:2.3:o:grandstream:gxp1630_firmware:1.0.7.49
-
cpe:2.3:o:grandstream:gxp1630_firmware:1.0.7.50
-
cpe:2.3:o:grandstream:gxp1630_firmware:1.0.7.56
-
cpe:2.3:o:grandstream:gxp1630_firmware:1.0.7.6
-
cpe:2.3:o:grandstream:gxp1630_firmware:1.0.7.64
-
cpe:2.3:o:grandstream:gxp1630_firmware:1.0.7.67
-
cpe:2.3:o:grandstream:gxp1630_firmware:1.0.7.70
-
cpe:2.3:o:grandstream:gxp1630_firmware:1.0.7.74
-
cpe:2.3:o:grandstream:gxp1630_firmware:1.0.7.79
-
cpe:2.3:o:grandstream:gxp1630_firmware:1.0.7.80