First published: Fri Jul 17 2020(Updated: )
Grandstream GWN7000 firmware version 1.0.9.4 and below allows authenticated remote users to modify the system's crontab via undocumented API. An attacker can use this functionality to execute arbitrary OS commands on the router.
Credit: vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
Grandstream GWN7000 firmware | <=1.0.9.4 | |
Grandstream GWN7000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-5756.
CVE-2020-5756 has a severity rating of 8.8 (critical).
CVE-2020-5756 allows authenticated remote users to modify the system's crontab via an undocumented API, enabling them to execute arbitrary OS commands on the router.
Grandstream GWN7000 firmware version 1.0.9.4 and below are affected by CVE-2020-5756.
To fix CVE-2020-5756, update the Grandstream GWN7000 firmware to version 1.0.9.5 or higher.