CVE-2020-5758

Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authenticated remote attacker can execute commands as the root user by sending a crafted HTTP GET to the UCM's "Old" HTTPS API.
References
Link Resource
https://www.tenable.com/security/research/tra-2020-42 Broken Link Third Party Advisory
https://www.tenable.com/cve/CVE-2020-5758 Not Applicable
Configurations

Configuration 1


Information

Published : 2020-07-17 09:15

Updated : 2020-07-23 02:29


NVD link : CVE-2020-5758

Mitre link : CVE-2020-5758

Products Affected
CWE