Executive brief
Grandstream GXP1628 VoIP phones are affected by a security flaw that allows unauthorized users to view internal system directories. By accessing these directories, an attacker could download sensitive configuration files or logs, potentially leading to the exposure of private communication data or device credentials. This could compromise the privacy of phone calls and the security of the corporate telephony network.
Technical details
The Grandstream GXP1628 VoIP phone (firmware <=1.0.4.130) is vulnerable to information disclosure due to incorrect access control (CWE-548). The device's web server is configured with directory listing enabled for sensitive paths such as /webapp/, /cgi-bin/, and /json/contents/. A remote attacker with low privileges can navigate to these directories via a web browser to enumerate and download sensitive files, including configuration data and logs. This exposure can be leveraged to facilitate further attacks or system compromise. Users are advised to check for firmware updates or manually disable directory listing if the configuration allows.
Affected products
- Grandstream Networks GXP1628 <=1.0.4.130
Timeline
- 2025-07-16: disclosed: Initial vulnerability report created on GitHub Gist
- 2025-07-29: advisory: CVE published to NVD