
CVE-2016-1519 – Grandstream Wave 1.0.1.26 TLS Man-In-The-Middle
https://notcve.org/view.php?id=CVE-2016-1519
18 Mar 2016 — The com.softphone.common package in the Grandstream Wave app 1.0.1.26 and earlier for Android does not properly validate SSL certificates, which allows man-in-the-middle attackers to spoof the Grandstream provisioning server via a crafted certificate. El paquete com.softphone.common en la Grandstream Wave app 1.0.1.26 y versiones anteriores para Android no valida adecuadamente certificados SSL, que permite a los atacantes man-in-the-middle suplantar el servidor de aprovisionamiento de Grandstream a través d... • http://packetstormsecurity.com/files/136290/Grandstream-Wave-1.0.1.26-TLS-Man-In-The-Middle.html • CWE-295: Improper Certificate Validation •

CVE-2016-1520 – Grandstream Wave 1.0.1.26 Update Redirection
https://notcve.org/view.php?id=CVE-2016-1520
18 Mar 2016 — The Grandstream Wave app 1.0.1.26 and earlier for Android does not use HTTPS when retrieving update information, which might allow man-in-the-middle attackers to execute arbitrary code via a crafted application. La Grandstream Wave app 1.0.1.26 y versiones anteriores para Android no utiliza HTTPS cuando recupera la información de actualización, lo que podría permitir que los atacantes man-in-the-middle ejecutar código arbitrario a través de una aplicación manipulada. The Grandstream Wave application version... • https://packetstorm.news/files/id/136291 • CWE-254: 7PK - Security Features •

CVE-2016-1518 – Grandstream Wave 1.0.1.26 Man-In-The-Middle
https://notcve.org/view.php?id=CVE-2016-1518
17 Mar 2016 — The auto-provisioning mechanism in the Grandstream Wave app 1.0.1.26 and earlier for Android and Grandstream Video IP phones allows man-in-the-middle attackers to spoof provisioning data and consequently modify device functionality, obtain sensitive information from system logs, and have unspecified other impact by leveraging failure to use an HTTPS session for downloading configuration files from http://fm.grandstream.com/gs/. El mecanismo de aprovisionamiento automático en la Grandstream Wave app 1.0.1.26... • http://packetstormsecurity.com/files/136280/Grandstream-Wave-1.0.1.26-Man-In-The-Middle.html • CWE-284: Improper Access Control •