CVE-2020-5722criticalunder attackCWE-89

CVE-2020-5722: critical vulnerability in Grandstream UCM6200 Series

Published · Updated

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 9.8epss 84%
from disclosure to weapon1 days
Published on NVDMar 23
1st PoC+1d
metasploitMar 23
CISA KEV+676d
exploitation probability
84%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
3 public exploit(s)
Action required by CISAfederal deadline: 2022-07-28

Apply updates per vendor instructions.

In short

The Grandstream UCM6200 phone system has an unprotected SQL injection flaw that allows attackers to send specially crafted requests and run commands with full system privileges, or inject malicious content into password recovery emails.

Technical detail

Unauthenticated remote SQL injection via HTTP interface enables arbitrary command execution as root (CWE-89). Attack vector requires crafted HTTP requests; no authentication bypass needed. Impact includes complete system compromise in affected versions (< 1.0.19.20) or email content manipulation (< 1.0.20.17).

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. An attacker can use this vulnerability to execute shell commands as root on versions before 1.0.19.20 or inject HTML in password recovery emails in versions before 1.0.20.17.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.