Grandstream GSD3710 Stack-based Buffer Overflow
48Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 9.8epss 4.3%
from disclosure to weapon986 days
Published on NVDSep 23
1st PoC+986d
exploitation probability
4.3%top 10% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
an attacker with knowledge of user/pass of Grandstream GSD3710 in its 1.0.11.13 version, could overflow the stack since it doesn't check the param length before use the strcopy instruction. The explotation of this vulnerability may lead an attacker to execute a shell with full access.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Grandstream · Grandstream GSD3710public PoCs found — 1
exploitdbwww.exploit-db.com/exploits/52313unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.