Grandstream Networks GXP1628 <=1.0.4.130 is vulnerable to Incorrect Access Control. The device is configured with directory listing enabled, allowing unauthorized access to sensitive directories and files.
The product inappropriately exposes a directory listing with an index of all the resources located inside of the directory.
Link | Tags |
---|---|
http://grandstream.com | product |
https://gist.github.com/Exek1el/928ea6fd06d3b48c1c91cfdc30317d8d | third party advisory exploit |