CVE-2019-10662: OS Command Injection
Published Mar 30, 2019
·Updated
Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the backupUCMConfig file-backup parameter to the /cgi? URI.
Affected Software
2 affected components
Grandstream Ucm6204 Firmware<1.0.19.20
Grandstream UCM6204
Event History
Mar 30, 2019
CVE Published
via MITRE·04:43 PM
Data Sourced
via MITRE·04:43 PM
Description
Frequently Asked Questions
1
What is CVE-2019-10662?
CVE-2019-10662 is a vulnerability found in Grandstream UCM6204 devices before version 1.0.19.20.
2
How can remote authenticated users exploit CVE-2019-10662?
Remote authenticated users can exploit CVE-2019-10662 by using shell metacharacters in the backupUCMConfig file-backup parameter to the /cgi? URI.
3
What is the severity of CVE-2019-10662?
The severity of CVE-2019-10662 is critical with a CVSS score of 8.8.
4
Which versions of Grandstream UCM6204 firmware are affected by CVE-2019-10662?
Grandstream UCM6204 devices before version 1.0.19.20 are affected by CVE-2019-10662.
5
How can I fix CVE-2019-10662?
To fix CVE-2019-10662, update your Grandstream UCM6204 device to version 1.0.19.20 or later.