Vulnerability Description
An issue in Grandstream UCM6510 v.1.0.20.52 and before allows a remote attacker to obtain sensitive information via the Login function at /cgi and /webrtccgi.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Grandstream | Ucm6510 Firmware | <= 1.0.20.52 |
| Grandstream | Ucm6510 | - |
Related Weaknesses (CWE)
References
- http://grandstream.comProduct
- http://ucm65xx.comBroken Link
- https://gist.github.com/Exek1el/a1fe4288f0df0a47068d618579c6b647Third Party Advisory
FAQ
What is CVE-2025-28171?
CVE-2025-28171 is a vulnerability with a CVSS score of 6.5 (MEDIUM). An issue in Grandstream UCM6510 v.1.0.20.52 and before allows a remote attacker to obtain sensitive information via the Login function at /cgi and /webrtccgi.
How severe is CVE-2025-28171?
CVE-2025-28171 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-28171?
Check the references section above for vendor advisories and patch information. Affected products include: Grandstream Ucm6510 Firmware, Grandstream Ucm6510.