CVE-2025-28170

Grandstream Networks GXP1628 <=1.0.4.130 is vulnerable to Incorrect Access Control. The device is configured with directory listing enabled, allowing unauthorized access to sensitive directories and files.
Configurations

No configuration.

History

31 Jul 2025, 18:42

Type Values Removed Values Added
Summary
  • (es) Grandstream Networks GXP1628 &lt;=1.0.4.130 es vulnerable a un control de acceso incorrecto. El dispositivo está configurado con el listado de directorios habilitado, lo que permite el acceso no autorizado a directorios y archivos confidenciales.

29 Jul 2025, 18:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.6
CWE CWE-548

29 Jul 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-29 17:15

Updated : 2025-07-31 18:42


NVD link : CVE-2025-28170

Mitre link : CVE-2025-28170

CVE.ORG link : CVE-2025-28170


JSON object : View

Products Affected

No product.

CWE
CWE-548

Exposure of Information Through Directory Listing