▲ 3 points
back
2 comments
The original advisory can be found here[0] and a Github repository with PoCs here[1].
[0] https://www.trustwave.com/en-us/resources/security-resources...
Grandstream doesn't care about security, they went over a year with a broken TLS reg stack on the DP750/DP720, and slightly under a year with the same exact issue on the HT802.
I'd be curious to see an audit of the DP750...