CVE-2020-25218
Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allow Authentication Bypass in its administrative web interface.
Published:Mar 29, 2021
Last Modified:Nov 21, 2024
EPS:Mar 29, 2021
EPSS Score:0.0036
CVSS Score:9.8
Affected Products
Vendor
Product
Action
Vendor
Grandstream
Product
Grp2612
Grandstream
Grp2612
Vendor
Grandstream
Product
Grp2612 Firmware
Grandstream
Grp2612 Firmware
Vendor
Grandstream
Product
Grp2612p
Grandstream
Grp2612p
Vendor
Grandstream
Product
Grp2612p Firmware
Grandstream
Grp2612p Firmware
Vendor
Grandstream
Product
Grp2612w
Grandstream
Grp2612w
Vendor
Grandstream
Product
Grp2612w Firmware
Grandstream
Grp2612w Firmware
Vendor
Grandstream
Product
Grp2613
Grandstream
Grp2613
Vendor
Grandstream
Product
Grp2613 Firmware
Grandstream
Grp2613 Firmware
Vendor
Grandstream
Product
Grp2614
Grandstream
Grp2614
Vendor
Grandstream
Product
Grp2614 Firmware
Grandstream
Grp2614 Firmware
Vendor
Grandstream
Product
Grp2615
Grandstream
Grp2615
Vendor
Grandstream
Product
Grp2615 Firmware
Grandstream
Grp2615 Firmware
Vendor
Grandstream
Product
Grp2616
Grandstream
Grp2616
Vendor
Grandstream
Product
Grp2616 Firmware
Grandstream
Grp2616 Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
