An issue in Grandstream UCM6510 v.1.0.20.52 and before allows a remote attacker to obtain sensitive information via the Login function at /cgi and /webrtccgi.
The product stores sensitive information without properly limiting read or write access by unauthorized actors.
Link | Tags |
---|---|
http://grandstream.com | product |
http://ucm65xx.com | broken link |
https://gist.github.com/Exek1el/a1fe4288f0df0a47068d618579c6b647 | third party advisory |