Grandstream GAC2500等都是美国潮流网络(Grandstream)公司的产品。Grandstream GAC2500是一款基于Android平台的商务会议电话设备。Grandstream GXP2200是一款IP电话。Grandstream GVC3202是一款全高清视频会议设备。 多款Grandstream产品中存在操作系统命令注入漏洞。该漏洞源于网络系统或产品在内存上执行操作时,未正确验证数据边界,导致向关联的其他内存位置上执行了错误的读写操作。攻击者可利用该漏洞导致缓冲区溢出或堆溢出
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2019-10663 | Grandstream UCM6204 SQL注入漏洞 | |
| CVE-2019-10662 | Grandstream UCM6204 命令操作系统命令注入漏洞 | |
| CVE-2019-10661 | Grandstream GXV3611IR_HD 授权问题漏洞 | |
| CVE-2019-10660 | Grandstream GXV3611IR_HD 命令操作系统命令注入漏洞 | |
| CVE-2019-10659 | Grandstream GXV3370和Grandstream WP820 命令操作系统命令注入漏洞 | |
| CVE-2019-10658 | Grandstream GWN7610 命令操作系统命令注入漏洞 | |
| CVE-2019-10657 | Grandstream GWN7610和Grandstream GWN7000 操作系统命令注入漏洞 | |
| CVE-2019-10656 | Grandstream GWN7000 命令操作系统命令注入漏洞 | |
| CVE-2019-10654 | Long Range Zip LZO 安全漏洞 | |
| CVE-2019-10652 | flatCore 安全漏洞 | |
| CVE-2019-10650 | ImageMagick Studio ImageMagick 缓冲区错误漏洞 | |
| CVE-2019-10649 | ImageMagick Studio ImageMagick 资源管理错误漏洞 | |
| CVE-2019-10648 | Robocode 输入验证错误漏洞 | |
| CVE-2019-10647 | ZZZCMS zzzphp 代码注入漏洞 | |
| CVE-2019-10646 | Wolf CMS Add Snippet模块跨站脚本漏洞 | |
| CVE-2019-10644 | HYBBS 跨站请求伪造漏洞 |
No comments yet