CVE-2025-28170
7.6Grandstream · GXP1628
Grandstream GXP1628 devices running firmware version 1.0.4.130 or earlier contain an incorrect access control flaw, allowing unauthorized directory listing and access to sensitive files.
Executive summary
The Grandstream GXP1628 IP phone is vulnerable to an incorrect access control flaw that permits unauthorized access to sensitive system files and directories.
Vulnerability
The device suffers from an incorrect access control vulnerability due to directory listing being enabled by default. This flaw allows an authenticated user with low privileges to traverse and access sensitive directories and files on the device.
Business impact
The ability for an unauthorized user to list directories and access sensitive files poses a significant risk to the confidentiality of the device configuration and potentially stored credentials. Given the CVSS score of 7.6, this vulnerability represents a high risk that could lead to full device compromise or lateral movement within the voice network.
Remediation
Immediate Action: Organizations should restrict network access to the administrative interface of the GXP1628 to trusted management subnets only. Verify if a firmware update is available from the vendor and apply it as soon as it is released.
Proactive Monitoring: Monitor network traffic for unusual GET requests to directories or attempts to access configuration files. Review device access logs for unauthorized attempts to navigate the file system.
Compensating Controls: Implement strict network segmentation to isolate IP phones from the main corporate network. Use a firewall to block all external access to the device web interface.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the referenced GitHub Gist.
Analyst recommendation
This vulnerability presents a high risk to organizational security due to the exposure of sensitive system data. Administrators should prioritize isolating affected devices from untrusted networks and check the vendor support page frequently for a firmware patch to address this access control failure.