CVE-2020-25217: Command Injection
Published Mar 29, 2021
·Updated
Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allows Command Injection as root in its administrative web interface.
Affected Software
14 affected components
Grandstream Grp2612 Firmware=1.0.3.6
Grandstream Grp2612
Grandstream Grp2612p Firmware=1.0.3.6
Grandstream Grp2612p
Grandstream Grp2612w Firmware=1.0.3.6
Grandstream Grp2612w
Grandstream Grp2613 Firmware=1.0.3.6
Grandstream Grp2613
Grandstream Grp2614 Firmware=1.0.3.6
Grandstream Grp2614
Grandstream Grp2615 Firmware=1.0.3.6
Grandstream Grp2615
Grandstream Grp2616 Firmware=1.0.3.6
Grandstream Grp2616
Event History
Mar 29, 2021
CVE Published
via MITRE·04:59 PM
Data Sourced
via MITRE·04:59 PM
Description
Frequently Asked Questions
1
What is CVE-2020-25217?
CVE-2020-25217 is a vulnerability found in the Grandstream GRP261x VoIP phone's administrative web interface.
2
What is the severity of CVE-2020-25217?
CVE-2020-25217 has a severity level of 7.2 (critical).
3
How can I exploit CVE-2020-25217?
CVE-2020-25217 allows command injection as root in the administrative web interface of the Grandstream GRP261x VoIP phone.
4
Is Grandstream GRP261x vulnerable to CVE-2020-25217?
Yes, Grandstream GRP261x with firmware version 1.0.3.6 is vulnerable to CVE-2020-25217.
5
How can I fix CVE-2020-25217?
To fix CVE-2020-25217, update the firmware of the Grandstream GRP261x VoIP phone to a version that is not affected.