Rapid7 disclosed CVE-2026-2329, a critical unauthenticated stack-based buffer overflow (CWE-121) in the Grandstream GXP1600 series VoIP phones that can be exploited for remote code execution (RCE) as root. The flaw is reachable via the phone’s web-based HTTP API in default configurations, specifically the endpoint /cgi-bin/api.values.get, and impacts all models sharing the common firmware image: GXP1610, GXP1615, GXP1620, GXP1625, GXP1628, and GXP1630. Public scoring cited includes CVSS v4.0 9.3 (Critical) with network attack vector and no privileges or user interaction required.
Rapid7 demonstrated exploitability by developing a Metasploit exploit module (plus a post-exploitation module) showing unauthenticated compromise of a vulnerable device (e.g., GXP1630 on firmware 1.0.7.79) and subsequent credential collection (including local and SIP accounts). Rapid7 also highlighted operational risk beyond device takeover: with root access, an attacker could alter SIP configuration to route calls through attacker-controlled infrastructure, enabling covert call interception. Grandstream has released a firmware fix, version 1.0.7.81, to remediate the issue, and the disclosure is tracked via Grandstream PSIRT and Metasploit references.

See affected versions and whether adversaries are exploiting it.
7 events from the most recent confirmed update back to the earliest known activity.
A pull request was opened to add a Nuclei template for safely detecting vulnerable Grandstream GXP1600 devices via the affected API endpoint. This expanded defender tooling beyond the Metasploit exploit and post-exploitation modules.
Public CVE tracking sources published CVE-2026-2329 as a high-severity issue affecting six Grandstream GXP1600 models, classifying it as CWE-121 and noting network-reachable unauthenticated exploitation. The entry linked to vendor and Rapid7 references, helping standardize public awareness of the bug.
Alongside its disclosure, Rapid7 released a Metasploit exploit module demonstrating root RCE and a post-exploitation module to extract stored secrets such as local and SIP credentials. The tooling also showed how compromised phones could be reconfigured to use attacker-controlled SIP infrastructure for call interception.
Rapid7 published coordinated disclosure details for CVE-2026-2329, describing a critical unauthenticated stack-based buffer overflow in the /cgi-bin/api.values.get endpoint that enables root remote code execution on Grandstream GXP1600 phones. The disclosure credited Stephen Fewer and explained the root cause, affected models, and exploitability conditions.
After issuing the firmware update, Grandstream publicly disclosed the security issue through its PSIRT and release-note channels. This made the existence of the flaw and the availability of a fix broadly known.
Grandstream released firmware version 1.0.7.81 to remediate the vulnerability affecting GXP1600-series phones. Reports place the patch release in early February 2026, with sources citing February 2 or February 3.
Rapid7 researcher Stephen Fewer reported the unauthenticated stack-based buffer overflow in Grandstream GXP1600-series VoIP phones to Grandstream in early January 2026, beginning coordinated disclosure. Some reporting indicates follow-up contact attempts were made later in January.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
10 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcegithub.com
Open sourcecybersecuritynews.com
Open sourcehelpnetsecurity.com
Open sourcecvefeed.io
Open sourcedarkreading.com
Open sourcerapid7.com
Open sourcerapid7.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.