Grandstream Networks GXP1628 <=1.0.4.130 is vulnerable to Incorrect Access Control. The device is configured with directory listing enabled, allowing unauthorized access to sensitive directories and files.
References
| Link | Resource |
|---|---|
| http://grandstream.com | Product |
| https://gist.github.com/Exek1el/928ea6fd06d3b48c1c91cfdc30317d8d | Third Party Advisory Exploit |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2025-07-29 17:15
Updated : 2025-08-06 20:46
NVD link : CVE-2025-28170
Mitre link : CVE-2025-28170
CVE.ORG link : CVE-2025-28170
JSON object : View
Products Affected
grandstream
- gxp1628
- gxp1628_firmware
CWE
CWE-548
Exposure of Information Through Directory Listing
