Information Disclosure Vulnerability in Grandstream GWN7660ELR Device
CVE-2026-93338

6.9MEDIUM

Key Information:

Vendor
CVE Published:
18 September 2026

What is CVE-2026-93338?

The Grandstream GWN7660ELR device prior to firmware version 1.0.27.6 is vulnerable to information disclosure through its SNMP v2c service. This vulnerability allows unauthenticated remote attackers to exploit the default community string 'public' to query sensitive system information. Attackers can obtain critical data such as operating system and kernel versions, running processes, network configurations, routing tables, ARP mappings, active TCP connections, and file system paths. This facilitates detailed reconnaissance of the affected device and its network, potentially leading to further exploitation.

Affected Version(s)

GWN7660ELR 0 < 1.0.27.6

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ahmed Embaby
.