CVE-2020-5722: critical vulnerability in Grandstream UCM6200 Series
Published · Updated
100Vexday Risk Score
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
ssvc Actcvss 9.8epss 84%
from disclosure to weapon1 days
Published on NVDMar 23
1st PoC+1d
metasploitMar 23
CISA KEV+676d
exploitation probability
84%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
3 public exploit(s)
Action required by CISAfederal deadline: 2022-07-28
Apply updates per vendor instructions.
In short
The Grandstream UCM6200 phone system has an unprotected SQL injection flaw that allows attackers to send specially crafted requests and run commands with full system privileges, or inject malicious content into password recovery emails.
Technical detail
Unauthenticated remote SQL injection via HTTP interface enables arbitrary command execution as root (CWE-89). Attack vector requires crafted HTTP requests; no authentication bypass needed. Impact includes complete system compromise in affected versions (< 1.0.19.20) or email content manipulation (< 1.0.20.17).
Summary generated and translated by AI from the official description.
The full analysis of this CVE is available in Portuguese →
The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. An attacker can use this vulnerability to execute shell commands as root on versions before 1.0.19.20 or inject HTML in password recovery emails in versions before 1.0.20.17.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · Grandstream UCM6200 Seriespublic PoCs found — 3
exploitdbwww.exploit-db.com/exploits/48247unverifiedcve_referencepacketstormsecurity.com/files/165708/Grandstream-UCM62xx-IP-PBX-sendPasswordEmail-Remote-Code-Execution.htmlunverifiedcve_referencepacketstormsecurity.com/files/156876/UCM6202-1.0.18.13-Remote-Command-Injection.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://packetstormsecurity.com/files/156876/UCM6202-1.0.18.13-Remote-Command-Injection.htmlhttp://packetstormsecurity.com/files/165708/Grandstream-UCM62xx-IP-PBX-sendPasswordEmail-Remote-Code-Execution.htmlhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-5722https://www.tenable.com/security/research/tra-2020-15