CVE-2020-5762: Null Pointer Dereference
Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to a denial of service attack against the TR-069 service. An unauthenticated remote attacker can stop the service due to a NULL pointer dereference in the TR-069 service. This condition is triggered due to mishandling of the HTTP Authentication field.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Grandstream firmware issue?
The vulnerability ID for this Grandstream firmware issue is CVE-2020-5762.
What is the severity of CVE-2020-5762?
The severity of CVE-2020-5762 is high with a CVSS score of 7.5.
How does the vulnerability in Grandstream HT800 series firmware version 1.0.17.5 and below manifest?
The vulnerability in Grandstream HT800 series firmware version 1.0.17.5 and below allows an unauthenticated remote attacker to launch a denial of service attack against the TR-069 service, causing it to crash.
How can an attacker exploit CVE-2020-5762?
An attacker can exploit CVE-2020-5762 by sending specially crafted requests to the TR-069 service, causing a NULL pointer dereference and crashing the service.
Is there a fix available for this vulnerability?
Yes, updating the Grandstream HT800 series firmware to version 1.0.17.6 or above will fix this vulnerability.