First published: Sat Mar 30 2019(Updated: )
Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the backupUCMConfig file-backup parameter to the /cgi? URI.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Grandstream Ucm6204 Firmware | <1.0.19.20 | |
Grandstream UCM6204 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-10662 is a vulnerability found in Grandstream UCM6204 devices before version 1.0.19.20.
Remote authenticated users can exploit CVE-2019-10662 by using shell metacharacters in the backupUCMConfig file-backup parameter to the /cgi? URI.
The severity of CVE-2019-10662 is critical with a CVSS score of 8.8.
Grandstream UCM6204 devices before version 1.0.19.20 are affected by CVE-2019-10662.
To fix CVE-2019-10662, update your Grandstream UCM6204 device to version 1.0.19.20 or later.