CVE-2020-5726: SQL Injection
The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the CTI server on port 8888. A remote unauthenticated attacker can invoke the challenge action with a crafted username and discover user passwords.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-5726?
CVE-2020-5726 is a vulnerability in the Grandstream UCM6200 series firmware before 1.0.20.22 that allows remote attackers to perform SQL injection via the CTI server on port 8888.
How can an attacker exploit CVE-2020-5726?
An attacker can exploit CVE-2020-5726 by invoking the challenge action with a crafted username and discovering user passwords.
What is the severity of CVE-2020-5726?
CVE-2020-5726 has a severity rating of 7.5 (high).
Which software versions are affected by CVE-2020-5726?
The Grandstream UCM6200 firmware versions up to 1.0.20.22 are affected by CVE-2020-5726.
Are the Grandstream UCM6202, UCM6204, and UCM6208 devices also affected?
No, the Grandstream UCM6202, UCM6204, and UCM6208 devices are not vulnerable to CVE-2020-5726.