CVE-2026-2329
An unauthenticated stack-based buffer overflow vulnerability exists in the HTTP API endpoint /cgi-bin/api.values.get. A remote attacker can leverage this vulnerability to achieve unauthenticated remote code execution (RCE) with root privileges on a target device. The vulnerability affects all six device models in the series: GXP1610, GXP1615, GXP1620, GXP1625, GXP1628, and GXP1630.
Published:Feb 18, 2026
Last Modified:Apr 17, 2026
EPS:Feb 18, 2026
EPSS Score:0.34822
CVSS Score:9.8
Affected Products
Vendor
Product
Action
Vendor
Grandstream
Product
Gxp1610
Grandstream
Gxp1610
Vendor
Grandstream
Product
Gxp1610 Firmware
Grandstream
Gxp1610 Firmware
Vendor
Grandstream
Product
Gxp1615
Grandstream
Gxp1615
Vendor
Grandstream
Product
Gxp1615 Firmware
Grandstream
Gxp1615 Firmware
Vendor
Grandstream
Product
Gxp1620
Grandstream
Gxp1620
Vendor
Grandstream
Product
Gxp1620 Firmware
Grandstream
Gxp1620 Firmware
Vendor
Grandstream
Product
Gxp1625
Grandstream
Gxp1625
Vendor
Grandstream
Product
Gxp1625 Firmware
Grandstream
Gxp1625 Firmware
Vendor
Grandstream
Product
Gxp1628
Grandstream
Gxp1628
Vendor
Grandstream
Product
Gxp1628 Firmware
Grandstream
Gxp1628 Firmware
Vendor
Grandstream
Product
Gxp1630
Grandstream
Gxp1630
Vendor
Grandstream
Product
Gxp1630 Firmware
Grandstream
Gxp1630 Firmware
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
