CVE-2024-32937

HIGH

Grandstream GXP2135 Firmware 1.0.9.129, 1.0.11.74, 1.0.11.79 - OS Command Injection via CWMP SelfDefinedTimeZone

Title source: llm
STIX 2.1

Description

An os command injection vulnerability exists in the CWMP SelfDefinedTimeZone functionality of Grandstream GXP2135 1.0.9.129, 1.0.11.74 and 1.0.11.79. A specially crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of malicious packets to trigger this vulnerability.

References (2)

Core 2

Scores

CVSS v3 8.1
EPSS 0.2629
EPSS Percentile 97.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (3)
grandstream/gxp2135_firmware 1.0.9.129
grandstream/gxp2135_firmware 1.0.11.74
grandstream/gxp2135_firmware 1.0.11.79
Published Jul 03, 2024
Tracked Since Feb 18, 2026