CVE-2025-28172 Details
Description
Grandstream Networks UCM6510 v1.0.20.52 and before is vulnerable to Improper Restriction of Excessive Authentication Attempts. An attacker can perform an arbitrary number of authentication attempts using different passwords and eventually gain access to the targeted account using a brute force attack.
A vulnerability exists in Grandstream Networks UCM6510 versions through 1.0.20.52, due to improper restriction of excessive authentication attempts. The device's weak account lockout mechanism allows attackers to perform unlimited login attempts using different passwords, potentially leading to unauthorized access. This issue is particularly exploitable through the '/cgi' and '/webrtccgi' endpoints, where the system's responses can be manipulated to facilitate brute force attacks.
Users can update to Grandstream UCM6510 firmware version 1.0.20.53, which addresses this vulnerability. The update is available on the Grandstream official firmware support page.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 29, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/Exek1el/6291185a87c98d4229181212b2bd5cdf | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-307 | Improper Restriction of Excessive Authentication Attempts | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| grandstream ucm6510 firmware | <= 1.0.20.52 |
CPE
Remediation
| |
| grandstream ucm6510 | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 5, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 6, 2025 | Initial Analysis | [email protected] |
| Jul 29, 2025 | CVE Modified | CISA-ADP |
| Jul 29, 2025 | New CVE Received | [email protected] |