CVE-2020-5756: OS Command Injection
Published Jul 17, 2020
·Updated
Grandstream GWN7000 firmware version 1.0.9.4 and below allows authenticated remote users to modify the system's crontab via undocumented API. An attacker can use this functionality to execute arbitrary OS commands on the router.
Affected Software
2 affected components
Grandstream GWN7000 firmware<=1.0.9.4
Grandstream GWN7000
Event History
Jul 17, 2020
CVE Published
via MITRE·08:16 PM
Data Sourced
via MITRE·08:16 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-5756.
2
What is the severity of CVE-2020-5756?
CVE-2020-5756 has a severity rating of 8.8 (critical).
3
How does CVE-2020-5756 affect Grandstream GWN7000 firmware?
CVE-2020-5756 allows authenticated remote users to modify the system's crontab via an undocumented API, enabling them to execute arbitrary OS commands on the router.
4
Which versions of Grandstream GWN7000 firmware are affected by CVE-2020-5756?
Grandstream GWN7000 firmware version 1.0.9.4 and below are affected by CVE-2020-5756.
5
How can I fix CVE-2020-5756?
To fix CVE-2020-5756, update the Grandstream GWN7000 firmware to version 1.0.9.5 or higher.