Rapid7 Labs conducted a zero-day research project against the Grandstream GXP1600 series of Voice over Internet Protocol (VoIP) phones, resulting in the discovery of a critical unauthenticated stack-based buffer overflow vulnerability, CVE-2026-2329.