A Malformed Input String to /cgi-bin/api-get_line_status on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to dump the device's configuration in cleartext.
| Software | From | Fixed in |
|---|---|---|
| grandstream / gxp1610_firmware | 1.0.4.128 | 1.0.4.128.x |
| grandstream / gxp1615_firmware | 1.0.4.128 | 1.0.4.128.x |
| grandstream / gxp1620_firmware | 1.0.4.128 | 1.0.4.128.x |
| grandstream / gxp1625_firmware | 1.0.4.128 | 1.0.4.128.x |
| grandstream / gxp1628_firmware | 1.0.4.128 | 1.0.4.128.x |
| grandstream / gxp1630_firmware | 1.0.4.128 | 1.0.4.128.x |