Aller au contenu
appaloosa scout logo main rounded
HIGH 7.8

CVE-2016-1520

The Grandstream Wave app 1.0.1.26 and earlier for Android does not use HTTPS when retrieving update information, which might allow man-in-the-middle attackers to execute arbitrary code via a crafted application.

CVSS v3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Configurations CPE vulnérables

Vendor Produit Plateforme Versions CPE 2.3 URI
grandstream wave Android ≤1.0.1.26 cpe:2.3:a:grandstream:wave:*:*:*:*:*:android:*:*
Voir sur NVD ↗