CVE-2015-2866
Grandstream GXV3611_HD Firmware < 1.0.3.6 - SQL Injection via TELNET Username
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2015-2866. PoCs published by pizza1337.
AI-analyzed exploit summary This exploit leverages a SQL injection vulnerability in Grandstream GXV3611_HD devices to reset the admin password and then uses a backdoor command to enable a telnet server on port 20000 with root access. The exploit is fully functional and demonstrates both authentication bypass and remote command execution.
Description
SQL injection vulnerability on the Grandstream GXV3611_HD camera with firmware before 1.0.3.9 beta allows remote attackers to execute arbitrary SQL commands by attempting to establish a TELNET session with a crafted username.
Exploits (1)
This exploit leverages a SQL injection vulnerability in Grandstream GXV3611_HD devices to reset the admin password and then uses a backdoor command to enable a telnet server on port 20000 with root access. The exploit is fully functional and demonstrates both authentication bypass and remote command execution.