Junglewise Threat Intelligence

CVE-2020-5722: Grandstream Networks UCM6200 Series SQL Injection Vulnerability

CVE-2020-5722 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-01-28

Vendors: Grandstream.

Executive brief

The HTTP interface of Grandstream UCM6200 series IP PBX devices is vulnerable to an unauthenticated remote SQL injection via crafted HTTP requests. Successful exploitation allows attackers to execute shell commands as root or inject malicious HTML into password recovery emails.

Affected products

  • Grandstream Networks UCM6200 Series Firmware before 1.0.19.20 (root shell execution); before 1.0.20.17 (HTML injection)

Timeline

  • 2020-03-23: disclosed: NVD Published Date
  • 2022-01-28: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-01-28: advisory: Publication date of the provided advisory summary