Grandstream GXP1600 VoIP Phones Exposed to Unauthenticated Remote Code Execution
A serious security vulnerability in the Grandstream GXP1600 line of VoIP phones has been discovered by cybersecurity researchers, which might provide an attacker access to vulnerable devices.
Tracked as CVE-2026-2329, the vulnerability has a CVSS score of 9.3 out of 10.0. It has been characterized as an instance of an unauthenticated stack-based buffer overflow that may cause remote code execution.
CVE-2026-2329 allows a remote attacker to get root capabilities and unauthenticated remote code execution (RCE) on a target device, according to Rapid7 researcher Stephen Fewer, who found and reported the vulnerability on January 6, 2026.
The cybersecurity firm claims that the problem stems from the web-based API service ("/cgi-bin/api.values.get") on the device, which is available by ...

