Description
Grandstream GWN7660ELR before firmware version 1.0.27.6 contains an information disclosure vulnerability that allows unauthenticated remote attackers to obtain sensitive system information by querying the SNMP v2c service configured with the default community string 'public'. Attackers can query standard MIBs over the SNMP port to retrieve operating system and kernel version, running process names and command-line arguments, network interface configuration, routing table entries, ARP table mappings, active TCP connection details, and file system paths, enabling detailed reconnaissance of the device and adjacent network infrastructure.
Published: 2026-09-18
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The vulnerability allows an unauthenticated attacker to query the SNMP v2c service with the default community string "public" and retrieve a wide range of sensitive data, including operating system details, process information, network configuration and active connections. This enables detailed reconnaissance of the device and surrounding network infrastructure, potentially facilitating further attacks.

Affected Systems

Grandstream Networks produces the GWN7660ELR device. Firmware versions prior to 1.0.27.6 are affected. No other versions or products are listed in the CNA data.

Risk and Exploitability

The CVSS score of 6.9 indicates a medium severity. The EPSS score of <1% indicates a low probability of exploitation and the vulnerability is not listed in the CISA KEV catalog, implying no confirmed exploits are circulating. The likely attack vector is remote SNMP traffic on the device's SNMP port; no special privileges or local access are required. An attacker reaching the SNMP port can exploit the default community string to extract sensitive information and conduct reconnaissance.

Generated by OpenCVE AI on September 19, 2026 at 17:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the device firmware to version 1.0.27.6 or later, which removes the default community string usage.
  • Change the SNMP community string from "public" to a strong, unique value if the service remains required, and enforce SNMP authentication.
  • Restrict SNMP traffic to trusted IP addresses using firewall rules or ACLs to limit exposure.

Generated by OpenCVE AI on September 19, 2026 at 17:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Grandstream Networks
Grandstream Networks gwn7660elr
Vendors & Products Grandstream Networks
Grandstream Networks gwn7660elr

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description Grandstream GWN7660ELR before firmware version 1.0.27.6 contains an information disclosure vulnerability that allows unauthenticated remote attackers to obtain sensitive system information by querying the SNMP v2c service configured with the default community string 'public'. Attackers can query standard MIBs over the SNMP port to retrieve operating system and kernel version, running process names and command-line arguments, network interface configuration, routing table entries, ARP table mappings, active TCP connection details, and file system paths, enabling detailed reconnaissance of the device and adjacent network infrastructure.
Title Grandstream GWN7660ELR < 1.0.27.6 Information Disclosure via SNMP Default Community String
Weaknesses CWE-1188
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Grandstream Networks Gwn7660elr
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-18T17:24:47.072Z

Reserved: 2026-09-17T18:41:40.756Z

Link: CVE-2026-93338

cve-icon Vulnrichment

Updated: 2026-09-18T17:24:39.503Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T17:17:05.793

Modified: 2026-09-22T20:29:59.707

Link: CVE-2026-93338

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:28:42Z

Weaknesses
  • CWE-1188

    Initialization of a Resource with an Insecure Default