Signal
CVE-2026-2329: unauthenticated RCE flaw disclosed in grandstream GXP1600 VoIP phones
Evidence first: scan the strongest sources, then decide whether to go deeper.
Published 2026-02-18 14:00 UTCUpdated 2026-02-18 16:35 UTC
rss
cvevulnerabilityrcevoipnetwork_devicespatching
Source links open
Source links and full evidence are open here. Archive history, compare-over-time, alerts, exports, API, integrations, and workflow are paid.
No card needed for the free brief.
Evidence trail (top sources)
top sources (2 domains)domains are deduped. counts indicate coverage, not truth.2 top sources shown
limited source diversity in top sources
Overview
Rapid7 Labs disclosed a critical memory-corruption flaw in Grandstream GXP1600-series VoIP phones that is reachable in default configurations via the device’s web-based API service. The issue (CVE-2026-2329) enables unauthenticated remote code execution with root privileges, and Rapid7 notes a vendor firmware update is available to remediate it; the disclosure was subsequently echoed by The Hacker News.
Entities
Rapid7GrandstreamMetasploit
Score total
1.25
Momentum 24h
3
Posts
3
Origins
2
Source types
1
Duplicate ratio
0%
Why now
- Rapid7 publicly disclosed CVE-2026-2329 and described impact and affected models
- Rapid7 reports a vendor firmware update (1.0.7.81) is available
- The issue is being amplified via mainstream security news coverage
Why it matters
- Unauthenticated RCE with root privileges raises takeover risk for VoIP endpoints
- Default-accessible web API exposure can widen the attack surface
- A published Metasploit module can accelerate validation and defensive testing
LLM analysis
Topic mix: lowPromo risk: lowSource quality: high
Recurring claims
- CVE-2026-2329 is a critical unauthenticated stack-based buffer overflow in Grandstream GXP1600 VoIP phones that can lead to remote code execution with root privileges.
- Rapid7 states a vendor firmware update (version 1.0.7.81) is available to fully remediate CVE-2026-2329.
How sources frame it
- Rapid7 Blog: neutral
- The Hacker News: neutral
Rapid7 disclosure + media pickup; focus on patch availability and unauthenticated RCE risk on VoIP endpoints.
All evidence
All evidence
Grandstream GXP1600 VoIP Phones Exposed to Unauthenticated Remote Code Execution
The Hacker News · thehackernews.com · 2026-02-18 16:35 UTC
The Phone is Listening: A Cold War–Style Vulnerability in Modern VoIP
Rapid7 Blog · rapid7.com · 2026-02-18 14:15 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 2Origin domains: 2Duplicates: -
Showing 2 / 0
Top publishers (this list)
- The Hacker News (1)
- Rapid7 Blog (1)
Top origin domains (this list)
- thehackernews.com (1)
- rapid7.com (1)