Loading
Generated remediation guidance and an executive summary. No account required.
The com.softphone.common package in the Grandstream Wave app 1.0.1.26 and earlier for Android does not properly validate SSL certificates, which allows man-in-the-middle attackers to spoof the Grandstream provisioning server via a crafted certificate.
Use CWE-295, Grandstream vendor hub and Wave product page to widen CVE-2016-1519 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2016-1518 and CVE-2016-1520 for nearby disclosures in the same product family.