Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-30706 | An os command injection vulnerability exists in the CWMP SelfDefinedTimeZone functionality of Grandstream GXP2135 1.0.9.129, 1.0.11.74 and 1.0.11.79. A specially crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of malicious packets to trigger this vulnerability. |
Tue, 04 Nov 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 04 Nov 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:o:grandstream:gxp2135_firmware:*:*:*:*:*:*:*:* | |
| Metrics |
ssvc
|
Thu, 04 Sep 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Grandstream
Grandstream gxp2135 Grandstream gxp2135 Firmware |
|
| CPEs | cpe:2.3:h:grandstream:gxp2135:-:*:*:*:*:*:*:* cpe:2.3:o:grandstream:gxp2135_firmware:1.0.11.74:*:*:*:*:*:*:* cpe:2.3:o:grandstream:gxp2135_firmware:1.0.11.79:*:*:*:*:*:*:* cpe:2.3:o:grandstream:gxp2135_firmware:1.0.9.129:*:*:*:*:*:*:* |
|
| Vendors & Products |
Grandstream
Grandstream gxp2135 Grandstream gxp2135 Firmware |
Status: PUBLISHED
Assigner: talos
Published:
Updated: 2025-11-04T17:20:20.384Z
Reserved: 2024-04-19T20:26:32.967Z
Link: CVE-2024-32937
Updated: 2025-11-04T17:20:20.384Z
Status : Modified
Published: 2024-07-03T14:15:05.340
Modified: 2025-11-04T18:16:20.503
Link: CVE-2024-32937
No data.
OpenCVE Enrichment
No data.
EUVD