Junglewise Threat Intelligence

CVE-2026-93338: Grandstream GWN7660ELR information disclosure via default SNMP community string

CVE-2026-93338 · Severity: medium · CVSS 5.3 · Published 2026-09-18

Vendors: Grandstream.

Executive brief

The Grandstream GWN7660ELR network switch contains a flaw allowing attackers to retrieve sensitive information without authentication via the SNMP service. An attacker can query the device over the network using the default SNMP community string to extract system details including OS version, running processes, network configuration, and routing tables—information that enables detailed reconnaissance of corporate network infrastructure.

Technical details

The vulnerability is an information disclosure issue in the SNMP v2c service, which is configured with the default community string 'public' and accessible unauthenticated over the network. An attacker can query standard MIBs to retrieve system metadata, process details, network interface and routing information, ARP tables, and active TCP connections. The issue is patched in firmware version 1.0.27.6 and later.

Affected products

  • Grandstream GWN7660ELR before 1.0.27.6

Timeline

  • 2026-09-18: disclosed

References