CVE-2020-5759: OS Command Injection
Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via SSH. An authenticated remote attacker can execute commands as the root user by issuing a specially crafted "unset" command.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Grandstream UCM6200 series firmware vulnerability?
The vulnerability ID for this Grandstream UCM6200 series firmware vulnerability is CVE-2020-5759.
What is the severity rating of CVE-2020-5759?
The severity rating of CVE-2020-5759 is 9.8 (Critical).
How can an attacker exploit CVE-2020-5759?
An authenticated remote attacker can exploit CVE-2020-5759 by issuing a specially crafted "unset" command via SSH, allowing them to execute commands as the root user.
Which versions of the Grandstream UCM6200 series firmware are vulnerable to CVE-2020-5759?
Grandstream UCM6200 series firmware versions 1.0.20.23 and below are vulnerable to CVE-2020-5759.
Where can I find more information about CVE-2020-5759?
You can find more information about CVE-2020-5759 at the following references: [Link 1](https://www.tenable.com/cve/CVE-2020-5759) and [Link 2](https://www.tenable.com/security/research/tra-2020-42).