Loading
Generated remediation guidance and an executive summary. No account required.
The auto-provisioning mechanism in the Grandstream Wave app 1.0.1.26 and earlier for Android and Grandstream Video IP phones allows man-in-the-middle attackers to spoof provisioning data and consequently modify device functionality, obtain sensitive information from system logs, and have unspecified other impact by leveraging failure to use an HTTPS session for downloading configuration files from http://fm.grandstream.com/gs/.
Use CWE-284, Grandstream vendor hub and Wave product page to widen CVE-2016-1518 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2016-1520 and CVE-2016-1519 for nearby disclosures in the same product family.