Home

Description

Grandstream Networks GXP1628 <=1.0.4.130 is vulnerable to Incorrect Access Control. The device is configured with directory listing enabled, allowing unauthorized access to sensitive directories and files.

PUBLISHED Reserved 2025-03-11 | Published 2025-07-29 | Updated 2025-07-29 | Assigner mitre

References

grandstream.com

gist.github.com/Exek1el/928ea6fd06d3b48c1c91cfdc30317d8d

cve.org (CVE-2025-28170)

nvd.nist.gov (CVE-2025-28170)

Download JSON