Rapid7

module

GrandStream GXP1600 Gather Credentials

Disclosed
N/A
Created
Feb 24, 2026

Description

This gather module works against Grandstream GXP1600 series VoIP devices and can collect HTTP, SIP, and TR-069
credentials from a device. You can first leverage the `exploit/linux/http/grandstream_gxp1600_unauth_rce` exploit
module to get a root session on a target GXP1600 series device before running this post module.

Author

sfewer-r7

Platform

Linux

Module Options

To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':


msf > use post/linux/gather/grandstream_gxp1600_creds
msf post(grandstream_gxp1600_creds) > show actions
...actions...
msf post(grandstream_gxp1600_creds) > set ACTION < action-name >
msf post(grandstream_gxp1600_creds) > show options
...show and set options...
msf post(grandstream_gxp1600_creds) > run

Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.