CVE-2026-2329 is a critical unauthenticated stack-based buffer overflow in the web-based HTTP API of Grandstream GXP1600-series VoIP phones. The flaw is reachable in the default configuration via the /cgi-bin/api.values.get endpoint over HTTP, where the request parameter is parsed as colon-delimited identifiers and copied into a fixed 64-byte stack buffer without proper bounds checking. Supplying an overly long attacker-controlled request value can overflow the stack, corrupt adjacent memory, and enable control of execution flow. Rapid7 reported that the vulnerable code is in the native /app/bin/gs_web component and that exploitation can be achieved remotely without authentication, resulting in remote code execution as root. The issue affects GXP1610, GXP1615, GXP1620, GXP1625, GXP1628, and GXP1630 devices running vulnerable firmware, with public Metasploit exploit and post-exploitation modules available. Firmware versions prior to 1.0.7.81 are described as affected in the provided content.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
61 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A stack overflow vulnerability in Grandstream GXP1600 VoIP devices that can grant attackers a root session (remote code execution).
A critical unauthenticated stack buffer overflow in Grandstream GXP1600 VoIP phones that can be exploited to gain root privileges; Metasploit modules are available and the issue is reported as fixed.
An unauthenticated stack overflow vulnerability in Grandstream GXP1600 VoIP devices enabling remote code execution and root access; follow-on activity includes credential theft and SIP traffic interception/packet capture once access is obtained.
An unauthenticated stack overflow leading to remote code execution (root) on Grandstream GXP1600-series VoIP devices, with follow-on modules for credential theft and SIP traffic capture.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.