{
"$type": "site.standard.document",
"bskyPostRef": {
"cid": "bafyreigulyxiu4r6364lfyolxhomvu6xcyq6sunuu62jwlzmmfmrlve4pi",
"uri": "at://did:plc:6wtxqaikjf62unmnajbfbq5v/app.bsky.feed.post/3mfiv7dw3sat2"
},
"coverImage": {
"$type": "blob",
"ref": {
"$link": "bafkreiesguvib3t37rgp5e5h4c6czvp7vlnsj5asawl22mcqi6a5w7ucpi"
},
"mimeType": "image/jpeg",
"size": 358178
},
"path": "/grandstream-gxp1600-voip-phones-face-critical-rce-vulnerability/",
"publishedAt": "2026-02-23T04:51:12.000Z",
"site": "https://vpncentral.com",
"tags": [
"News",
"Grandstream GXP1600 VoIP Phones Face Critical RCE Vulnerability",
"VPN Central"
],
"textContent": "Grandstream GXP1600 series VoIP phones suffer from CVE-2026-2329, a critical unauthenticated stack buffer overflow with CVSS score 9.3. Remote attackers gain root access via the web API endpoint “/cgi-bin/api.values.get” in default configs. No login required. Rapid7 researcher Stephen Fewer found the flaw January 6, 2026. The API parses colon-delimited “request” parameters like “68:phone_model” into a […]\n\nThe post Grandstream GXP1600 VoIP Phones Face Critical RCE Vulnerability appeared first on VPN Central.",
"title": "Grandstream GXP1600 VoIP Phones Face Critical RCE Vulnerability"
}