Impact
The vulnerability allows an unauthenticated attacker to query the SNMP v2c service with the default community string "public" and retrieve a wide range of sensitive data, including operating system details, process information, network configuration and active connections. This enables detailed reconnaissance of the device and surrounding network infrastructure, potentially facilitating further attacks.
Affected Systems
Grandstream Networks produces the GWN7660ELR device. Firmware versions prior to 1.0.27.6 are affected. No other versions or products are listed in the CNA data.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity. The EPSS score of <1% indicates a low probability of exploitation and the vulnerability is not listed in the CISA KEV catalog, implying no confirmed exploits are circulating. The likely attack vector is remote SNMP traffic on the device's SNMP port; no special privileges or local access are required. An attacker reaching the SNMP port can exploit the default community string to extract sensitive information and conduct reconnaissance.
OpenCVE Enrichment