CVE Tools

GXP1628 Firmware

7 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for GXP1628 Firmware, a product in the communications space. Use it to gauge the current risk picture and drill into individual advisories.

GXP1628 Firmware CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
GXP1628 Firmware CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-071
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-021
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 7 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical343%
  • High343%
  • Medium114%

Latest CVEs

The 7 most recently published vulnerabilities affecting GXP1628 Firmware.

  1. CVE-2026-2329Grandstream GXP1600 VoIP Phones - Unauthenticated stack buffer overflow9.8
  2. CVE-2025-28170Grandstream Networks GXP1628 <=1.0.4.130 is vulnerable to Incorrect Access Control. The device is configured with directory listing enabled, allowing unauthorized access to sensitive directories an...7.6
  3. CVE-2020-5739Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker adds an OpenVPN up script to the phone's VPN settings via the "Addit...8.8
  4. CVE-2020-5738Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker uploads a specially crafted tar file to the HTTP /cgi-bin/upload_vpn...8.8
  5. CVE-2018-17565Shell Metacharacter Injection in the SSH configuration interface on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to execute arbitrary system commands and gain a root shell.9.8
  6. CVE-2018-17564A Malformed Input String to /cgi-bin/delete_CA on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to delete configuration parameters and gain admin access to the device.9.8
  7. CVE-2018-17563A Malformed Input String to /cgi-bin/api-get_line_status on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to dump the device's configuration in cleartext.5.3

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store