Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The auto-provisioning mechanism in the Grandstream Wave app 1.0.1.26 and earlier for Android and Grandstream Video IP phones allows man-in-the-middle attackers to spoof provisioning data and consequently modify device functionality, obtain sensitive information from system logs, and have unspecified other impact by leveraging failure to use an HTTPS session for downloading configuration files from http://fm.grandstream.com/gs/.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Grandstream Video IP电话和Grandstream Wave app for Android 安全漏洞
Vulnerability Description
Grandstream Wave app for Android和Grandstream Video IP phones都是美国潮流网络(Grandstream )公司的产品。前者是一套用于Android系统免费的网络电话应用程序;后者是一款IP视频电话。auto-provisioning mechanism是用于其中的一种自动配置机制。 Grandstream Video IP电话和基于Android平台的Grandstream Wave app 1.0.1.26及之前的版本的auto-provisio
CVSS Information
N/A
Vulnerability Type
N/A