CVE-2019-10658 is a critical vulnerability affecting Grandstream GWN7610 devices running firmware prior to version 1.0.8.18. It allows remote authenticated attackers to execute arbitrary code by injecting shell metacharacters into the filename parameter of the update_nds_webroot_from_tmp API call. This vulnerability carries a CVSS score of 8.8 (High), indicating a severe risk with low attack complexity and high impact on confidentiality, integrity, and availability. While no public exploits (Metasploit, Nuclei, ExploitDB) are currently available and there's minimal community discussion or media coverage, the potential for remote code execution makes patching imperative.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.8.18CPE matchmatch criteria | cpe:2.3:o:grandstream:gwn7610_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.