CVE-2025-28171

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
29/07/2025
Last modified:
06/08/2025

Description

An issue in Grandstream UCM6510 v.1.0.20.52 and before allows a remote attacker to obtain sensitive information via the Login function at /cgi and /webrtccgi.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:grandstream:ucm6510_firmware:*:*:*:*:*:*:*:* 1.0.20.52 (including)
cpe:2.3:h:grandstream:ucm6510:-:*:*:*:*:*:*:*