Loading
Generated remediation guidance and an executive summary. No account required.
The Grandstream Wave app 1.0.1.26 and earlier for Android does not use HTTPS when retrieving update information, which might allow man-in-the-middle attackers to execute arbitrary code via a crafted application.
Use CWE-254, Grandstream vendor hub and Wave product page to widen CVE-2016-1520 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2016-1518 and CVE-2016-1519 for nearby disclosures in the same product family.