CVE-2020-5758: OS Command Injection
Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authenticated remote attacker can execute commands as the root user by sending a crafted HTTP GET to the UCM's "Old" HTTPS API.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-5758?
The severity of CVE-2020-5758 is critical with a CVSS score of 8.8.
How does CVE-2020-5758 affect Grandstream UCM6200 series firmware?
CVE-2020-5758 allows an authenticated remote attacker to execute OS commands as the root user by sending a crafted HTTP GET to the UCM's "Old" HTTPS API.
Which versions of Grandstream UCM6200 series firmware are affected by CVE-2020-5758?
Grandstream UCM6200 series firmware version 1.0.20.23 and below are affected by CVE-2020-5758.
How can an attacker exploit CVE-2020-5758?
An attacker can exploit CVE-2020-5758 by sending a specially crafted HTTP GET request to the UCM's "Old" HTTPS API.
Is Grandstream UCM6202 firmware version 1.0.20.23 vulnerable to CVE-2020-5758?
Yes, Grandstream UCM6202 firmware version 1.0.20.23 is vulnerable to CVE-2020-5758.