Junglewise Threat Intelligence

CVE-2025-28171: Grandstream UCM6510 user enumeration in login function

CVE-2025-28171 · Severity: medium · CVSS 6.5 · Published 2025-07-29

Executive brief

Grandstream UCM series IP PBX devices, which manage business telephone systems and communications, are affected by a security flaw in their login interface. An unauthorized remote attacker can systematically test for valid usernames by observing different error responses from the system. This information can be used to facilitate more targeted attacks, such as password guessing or account takeovers, potentially compromising the organization's communication infrastructure.

Technical details

A user enumeration vulnerability exists in the Grandstream UCM6510 (v1.0.20.52 and prior) and UCM630X series. The flaw is located within the /cgi and /webrtccgi endpoints used by Grandstream Wave. By sending requests with the 'action=challenge' or 'action=login' parameters, an attacker can distinguish between valid and invalid usernames based on the returned status codes (e.g., status 0 vs -37 for challenges). This is classified as insecure storage or handling of sensitive information (CWE-922). The issue is resolved in UCM6510 firmware version 1.0.20.53 and UCM630X firmware version 1.0.29.11.

Affected products

  • Grandstream UCM6510 firmware 1.0.20.52 and earlier
  • Grandstream UCM630X firmware (beta) versions prior to 1.0.29.11

Timeline

  • 2025-07-16: disclosed: Initial vulnerability report via GitHub Gist
  • 2025-07-29: advisory: CVE published to NVD
  • 2025-07-29: patched: Firmware updates 1.0.20.53 (UCM6510) and 1.0.29.11 (UCM630X) released

References

Related threats