CVE-2024-32937
CVE-2024-32937 is an os command injection vulnerability found in Grandstream GXP2135 phones. This flaw allows an attacker to execute arbitrary commands by sending specially crafted network packets to the affected device, specifically exploiting the CWMP SelfDefinedTimeZone functionality. The vulnerability affects versions 1.0.9.129, 1.0.11.74 and 1.0.11.79. While the CVSS score is 0, indicating a base score, the SOCRadar Vulnerability Risk Score (SVRS) of 30 suggests a moderate level of risk, requiring monitoring for potential exploitation. Successful exploitation can lead to complete system compromise. This is a significant concern, especially given the 'In The Wild' tag, suggesting active exploitation, and requires immediate investigation and patching to prevent unauthorized access and control of the Grandstream GXP2135 phone.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.