Back

HIGH

DLL search order hijack in Wave by Grandstream Networks

Published Sep 10, 2025

Description

DLL search order hijacking vulnerability in the wave.exe executable for Windows 11, version 1.27.8. Exploitation of this vulnerability could allow attackers with local access to execute arbitrary code by placing an arbitrary file in the 'C:\Users<user>\AppData\Local\Temp' directory, which could lead to arbitrary code execution and persistence. This vulnerability is only replicable in versions of Windows 11 and does not affect earlier versions.

Affected products

Remediation

Vendor solution

The vulnerability has been fixed by the Grandstream Networks team in the 1.27.11 version.

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner INCIBE
Published Sep 10, 2025
Updated Sep 10, 2025
Reserved Apr 16, 2025
CISA Vulnrichment
Updated Sep 10, 2025
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a