10

CVE-2020-25218

Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allow Authentication Bypass in its administrative web interface.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GrandstreamGrp2612 Firmware Version1.0.3.6
   GrandstreamGrp2612 Version-
GrandstreamGrp2612p Firmware Version1.0.3.6
   GrandstreamGrp2612p Version-
GrandstreamGrp2612w Firmware Version1.0.3.6
   GrandstreamGrp2612w Version-
GrandstreamGrp2613 Firmware Version1.0.3.6
   GrandstreamGrp2613 Version-
GrandstreamGrp2614 Firmware Version1.0.3.6
   GrandstreamGrp2614 Version-
GrandstreamGrp2615 Firmware Version1.0.3.6
   GrandstreamGrp2615 Version-
GrandstreamGrp2616 Firmware Version1.0.3.6
   GrandstreamGrp2616 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.3% 0.525
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-306 Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.