Grandstream Networks A.I CyberSecurity Scoring
Grandstream Networks
Company Information
Website:http://www.grandstream.com
Employees number:216
Number of followers:25,170
NAICS:517
Industry Type:Telecommunications
Homepage:grandstream.com
Grandstream Networks Risk Score (AI oriented)
Between 750 and 799
Grandstream NetworksTelecommunications
Updated:
01/04/2026
01/04/2026
751/1000
Fair
Baa
Grandstream Networks Global Score (TPRM)
xxxx
Grandstream NetworksTelecommunications
Score locked

Grandstream NetworksFair
Current Score
751Baa (FAIR)
01000
1 incidents
-3 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
752
JULY 2026
752
JUNE 2026
752
MAY 2026
752
APRIL 2026
752
MARCH 2026
751
FEBRUARY 2026
751
JANUARY 2026
754
Vulnerability
06 Jan 2026 • Grandstream Networks
Grandstream: Remote Code Execution Flaw In Grandstream GXP1600 Phones Exposed With PoC Exploit
Critical Zero-Day in Grandstream VoIP Phones Enables Unauthenticated Remote Code Execution
751
CRITICAL-3
GRA1771961536
Critical Zero-Day in Grandstream VoIP Phones Enables Unauthenticated Remote Code Execution
A severe zero-day vulnerability (CVE-2026-2329) in Grandstream’s GXP1600 series VoIP phones allows unauthenticated remote code execution (RCE) with root privileges. The flaw, a stack-based buffer overflow (CWE-121), affects the web-based API service on TCP port 80, accessible in default configurations without authentication.
All six models GXP1610, GXP1615, GXP1620, GXP1625, GXP1628, and GXP1630 share the same vulnerable firmware (versions up to 1.0.7.79). With a CVSSv4 score of 9.3 (Critical), the vulnerability enables low-complexity attacks from the network, posing significant risks to organizations using these devices for sensitive voice communications.
The issue stems from improper bounds checking in the `/cgi-bin/api.values.Get` endpoint, where a fixed 64-byte stack buffer (`small_buffer`) overflows when processing maliciously crafted HTTP POST requests. Exploitation corrupts adjacent stack memory, including the program counter (PC), allowing attackers to execute arbitrary code via return-oriented programming (ROP) chains. Security mitigations like RELRO, stack canaries, and PIE are absent, though the NX bit prevents direct stack execution.
Grandstream released firmware version 1.0.7.81 on January 30, 2026, patching the flaw. Rapid7 developed Metasploit modules for exploitation, including a post-exploitation tool to extract SIP credentials, enabling attackers to intercept calls, conduct toll fraud, or impersonate users. Public proof-of-concept (PoC) code further increases the threat, particularly for exposed devices in finance, government, or small businesses.
Discovered by researcher Stephen Fewer on January 6, 2026, the vulnerability underwent coordinated disclosure, with no reported wild exploitation to date. However, the trivial exploitability makes it attractive to opportunistic attackers and advanced persistent threats (APTs). Mitigation requires immediate firmware updates, network segmentation to isolate VoIP devices, and disabling web interfaces where possible.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
DECEMBER 2025
754
NOVEMBER 2025
754
OCTOBER 2025
754
SEPTEMBER 2025
754
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Grandstream Networks ??
What was Grandstream Networks's A.I Rankiteo Cyber Score in July 2026 ??
What was Grandstream Networks's A.I Rankiteo Cyber Score in June 2026 ??
What was Grandstream Networks's A.I Rankiteo Cyber Score in May 2026 ??
What was Grandstream Networks's A.I Rankiteo Cyber Score in April 2026 ??
What was Grandstream Networks's A.I Rankiteo Cyber Score in March 2026 ??
What was Grandstream Networks's A.I Rankiteo Cyber Score in February 2026 ??
What was Grandstream Networks's A.I Rankiteo Cyber Score in January 2026 ??
What was Grandstream Networks's A.I Rankiteo Cyber Score in December 2025 ??
What was Grandstream Networks's A.I Rankiteo Cyber Score in November 2025 ??
What was Grandstream Networks's A.I Rankiteo Cyber Score in October 2025 ??
What was Grandstream Networks's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on Grandstream Networks's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Grandstream Networks ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Grandstream Networks's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?