#10
The Hacker News
general
February 18, 2026 at 16:35 UTC
Grandstream GXP1600 VoIP Phones Exposed to Unauthenticated Remote Code Execution
By [email protected] (The Hacker News)
AI Summary
Critical vulnerability CVE-2026-2329 (CVSS 9.3) in Grandstream GXP1600 VoIP phones allows unauthenticated remote code execution via stack-based buffer overflow. The flaw enables attackers to seize complete control of affected business phone systems without authentication.
Relevance score: 78.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →