CVE-2022-2070
CRITICALGrandstream Gds3710 Firmware - Out-of-Bounds Write
Title source: ruleDescription
In Grandstream GSD3710 in its 1.0.11.13 version, it's possible to overflow the stack since it doesn't check the param length before using the sscanf instruction. Because of that, an attacker could create a socket and connect with a remote IP:port by opening a shell and getting full access to the system. The exploit affects daemons dbmng and logsrv that are running on ports 8000 and 8001 by default.
Exploits (1)
Scores
CVSS v3
9.8
EPSS
0.0944
EPSS Percentile
92.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-121
CWE-787
Status
published
Products (1)
grandstream/gds3710_firmware
1.0.11.13
Published
Sep 23, 2022
Tracked Since
Feb 18, 2026