Grandstream Networks GXP1628 <=1.0.4.130 is vulnerable to Incorrect Access Control. The device is configured with directory listing enabled, allowing unauthorized access to sensitive directories and files.
The product inappropriately exposes a directory listing with an index of all the resources located inside of the directory.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Gxp1628_firmware | Grandstream | * | 1.0.4.130 (including) |