CVE-2020-5760: OS Command Injection
Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to an OS command injection vulnerability. Unauthenticated remote attackers can execute arbitrary commands as root by crafting a special configuration file and sending a crafted SIP message.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-5760?
CVE-2020-5760 is a vulnerability in Grandstream HT800 series firmware version 1.0.17.5 and below that allows unauthenticated remote attackers to execute arbitrary commands as root.
How can an attacker exploit CVE-2020-5760?
An attacker can exploit CVE-2020-5760 by crafting a special configuration file and sending a crafted SIP message.
What is the severity of CVE-2020-5760?
The severity of CVE-2020-5760 is critical with a CVSS score of 7.8.
Which versions of Grandstream HT800 series firmware are affected by CVE-2020-5760?
Grandstream HT800 series firmware version 1.0.17.5 and below are affected by CVE-2020-5760.
Are all models of Grandstream HT800 series vulnerable to CVE-2020-5760?
No, only the models with firmware version 1.0.17.5 and below are vulnerable to CVE-2020-5760.