Grandstream Networks UCM6510 v1.0.20.52 and before is vulnerable to Improper Restriction of Excessive Authentication Attempts. An attacker can perform an arbitrary number of authentication attempts using different passwords and eventually gain access to the targeted account using a brute force attack.
References
Link | Resource |
---|---|
http://grandstream.com | Product |
https://gist.github.com/Exek1el/6291185a87c98d4229181212b2bd5cdf | Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
06 Aug 2025, 20:53
Type | Values Removed | Values Added |
---|---|---|
References | () http://grandstream.com - Product | |
References | () https://gist.github.com/Exek1el/6291185a87c98d4229181212b2bd5cdf - Third Party Advisory | |
CPE | cpe:2.3:o:grandstream:ucm6510_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:grandstream:ucm6510:-:*:*:*:*:*:*:* |
|
First Time |
Grandstream ucm6510 Firmware
Grandstream ucm6510 Grandstream |
31 Jul 2025, 18:42
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
29 Jul 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
CWE | CWE-307 |
29 Jul 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-07-29 15:15
Updated : 2025-08-06 20:53
NVD link : CVE-2025-28172
Mitre link : CVE-2025-28172
CVE.ORG link : CVE-2025-28172
JSON object : View
Products Affected
grandstream
- ucm6510
- ucm6510_firmware
CWE
CWE-307
Improper Restriction of Excessive Authentication Attempts