Cybersecurity researchers have uncovered a critical security flaw in the Grandstream GXP1600 series of VoIP, which could allow an attacker to take control of vulnerable devices.
See also: Anthropic's DXT has a "critical RCE vulnerability"

The vulnerability, tracked as CVE-2026-2329, has a CVSS score of 9.3 out of a maximum of 10.0. It is described as an unauthenticated stack-based buffer overflow, which could lead to remote code execution.
“ A remote attacker can exploit CVE-2026-2329 to achieve unauthenticated remote code execution (RCE) with root privileges on a targeted device ,” said Rapid7 researcher Stephen Fewer , who discovered and reported the bug on January 6, 2026.
According to the cybersecurity firm, the issue is located in the device's web-based API service (“/cgi-bin/api.values.get”) and is accessible in a default setting without requiring authentication.
This endpoint is designed to retrieve one or more configuration values from the phone, such as the firmware version number or model, via a colon-separated string in the “request” parameter (e.g., “request=68:phone_model”), which is then parsed to extract each identifier and add it to a 64-byte buffer on the stack.
See also: BeyondTrust fixes critical RCE vulnerability in Remote Support and PRA

This means that a malicious colon-separated “request” parameter, sent as part of an HTTP request to the “/cgi-bin/api.values.get“ endpoint, can be used to cause a stack-based buffer overflow, allowing attackers to corrupt the contents of the stack and ultimately achieve remote code execution on the underlying operating system.
The vulnerability affects the GXP1610, GXP1615, GXP1620, GXP1625, GXP1628 and GXP1630. It was addressed as part of a firmware update (version 1.0.7.81) released late last month.
In a Metasploit exploit module developed by Rapid7, it has been demonstrated that the vulnerability could be exploited to gain root privileges on a vulnerable device and combined with a post-exploit component to extract credentials stored on a compromised device.
See also: SmarterMail fixes critical RCE vulnerability

Additionally, remote code execution capabilities can be used to reconfigure the targeted device to use a malicious SIP proxy server, essentially allowing the attacker to intercept phone calls to and from the device and eavesdrop on VoIP conversations. A SIP proxy server is an intermediary server in VoIP networks for establishing and managing voice/video calls between endpoints.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
