Loading
Generated remediation guidance and an executive summary. No account required.
Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker adds an OpenVPN up script to the phone's VPN settings via the "Additional Settings" field in the web interface. When the VPN's connection is established, the user defined script is executed with root privileges.
Use CWE-94, Grandstream vendor hub and Gxp1610 Firmware product page to widen CVE-2020-5739 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2018-17565, CVE-2018-17564 and CVE-2026-2329 for nearby disclosures in the same product family.