Grandstream GXV3175 Unauthenticated Command Execution

Discussion in 'News Aggregator' started by Packet Storm, 21 Jan 2022.

  1. Packet Storm

    Packet Storm Guest

    This Metasploit module exploits a command injection vulnerability in Grandstream GXV3175 IP multimedia phones. The settimezone action does not validate input in the timezone parameter allowing injection of arbitrary commands. A buffer overflow in the phonecookie cookie parsing allows authentication to be bypassed by providing an alphanumeric cookie 93 characters in length. This module was tested successfully on Grandstream GXV3175v2 hardware revision V2.6A with firmware version 1.0.1.19.

    Continue reading...
     

Share This Page

Loading...