Grandstream HT800 series firmware version 1.0.17.5 and below contain a backdoor in the SSH service. An authenticated remote attacker can obtain a root shell by correctly answering a challenge prompt.
The product is released with debugging code still enabled or active.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ht801_firmware | Grandstream | * | 1.0.17.5 (including) |