Executive brief
The HTTP interface of Grandstream UCM6200 series IP PBX devices is vulnerable to an unauthenticated remote SQL injection via crafted HTTP requests. Successful exploitation allows attackers to execute shell commands as root or inject malicious HTML into password recovery emails.
Affected products
- Grandstream Networks UCM6200 Series Firmware before 1.0.19.20 (root shell execution); before 1.0.20.17 (HTML injection)
Timeline
- 2020-03-23: disclosed: NVD Published Date
- 2022-01-28: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-01-28: advisory: Publication date of the provided advisory summary