Vulnerabilities (CVE)

Filtered by vendor Grandstream Subscribe
Filtered by product Wave
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-1518 1 Grandstream 1 Wave 2023-12-10 6.8 MEDIUM 8.1 HIGH
The auto-provisioning mechanism in the Grandstream Wave app 1.0.1.26 and earlier for Android and Grandstream Video IP phones allows man-in-the-middle attackers to spoof provisioning data and consequently modify device functionality, obtain sensitive information from system logs, and have unspecified other impact by leveraging failure to use an HTTPS session for downloading configuration files from http://fm.grandstream.com/gs/.
CVE-2016-1519 1 Grandstream 1 Wave 2023-12-10 4.3 MEDIUM 5.9 MEDIUM
The com.softphone.common package in the Grandstream Wave app 1.0.1.26 and earlier for Android does not properly validate SSL certificates, which allows man-in-the-middle attackers to spoof the Grandstream provisioning server via a crafted certificate.
CVE-2016-1520 1 Grandstream 1 Wave 2023-12-10 6.8 MEDIUM 7.8 HIGH
The Grandstream Wave app 1.0.1.26 and earlier for Android does not use HTTPS when retrieving update information, which might allow man-in-the-middle attackers to execute arbitrary code via a crafted application.