AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2019-10655

CRITICAL · CVSS 9.8 EPSS 15.35% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-03-30 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit remote code execution code execution
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2019-10655
Severity
CRITICAL
CVSS
9.8
EPSS
15.35%

Original NVD Description

Grandstream GAC2500 1.0.3.35, GXP2200 1.0.3.27, GVC3202 1.0.3.51, GXV3275 before 1.0.3.219 Beta, and GXV3240 before 1.0.3.219 Beta devices allow unauthenticated remote code execution via shell metacharacters in a /manager?action=getlogcat priority field, in conjunction with a buffer overflow (via the phonecookie cookie) to overwrite a data structure and consequently bypass authentication. This can be exploited remotely or via CSRF because the cookie can be placed in an Accept HTTP header in an XMLHttpRequest call to lighttpd.

Related CVEs

Other vulnerabilities affecting the same vendor(s)