Brendan Scarvell
9 exploits
Active since Mar 2019
Grandstream GAC2500/GXP2200/GVC3202/GXV3275/GXV3240 < 1.0.3.219 - Unauthenticated RCE via getlogcat
CVSS 9.8
Grandstream GWN7000 Firmware < 1.0.6.32 - Authenticated Remote Code Execution via uci.apply API
CVSS 8.8
Grandstream GWN7000 < 1.0.6.32 and GWN7610 < 1.0.8.18 - Authenticated Password Exposure via Ubus UCI Config Request
CVSS 6.5
Grandstream GWN7610 < 1.0.8.18 - Authenticated Remote Code Execution via update_nds_webroot_from_tmp API
CVSS 8.8
Grandstream GXV3370 < 1.0.1.41 and WP820 < 1.0.3.6 - Authenticated Remote Code Execution via Logcat Priority Field
CVSS 8.8
Grandstream GXV3611IR_HD < 1.0.3.23 - Authenticated OS Command Injection via logserver Parameter
CVSS 8.8
Grandstream GXV3611IR_HD Firmware < 1.0.3.23 - Unauthenticated Root Access via Default Credentials
CVSS 9.8
Grandstream UCM62xx IP PBX sendPasswordEmail RCE
CVSS 8.8
Grandstream GAC2500/GXP2200/GVC3202/GXV3275/GXV3240 < 1.0.3.219 - Unauthenticated RCE via getlogcat
CVSS 9.8