A Malformed Input String to /cgi-bin/delete_CA on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to delete configuration parameters and gain admin access to the device.Referenceshttp://grandstream.com/support/firmwarehttps://iridiumxor.wordpress.com/2019/01/03/three-simple-cves-for-a-good-voip-phone/