Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via SSH. An authenticated remote attacker can execute commands as the root user by issuing a specially crafted "unset" command.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HGrandstream Ucm6202
HWGrandstreamall versionsGrandstream Ucm6202 Firmware
OSGrandstream≤ 1.0.20.23Grandstream Ucm6204
HWGrandstreamall versionsGrandstream Ucm6204 Firmware
OSGrandstream≤ 1.0.20.23Grandstream Ucm6208
HWGrandstreamall versionsGrandstream Ucm6208 Firmware
OSGrandstream≤ 1.0.20.23
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
Related vulnerabilities
CVE-2020-5757CRITICAL9.8PL ✓same product
Command injection w Grandstream UCM6200 — wykonanie kodu jako root
CVE-2020-5723CRITICAL9.8PL ✓same product
Grandstream UCM6200 — niezaszyfrowane hasła użytkowników w bazie SQLite
CVE-2020-5758HIGH8.8same product
Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP...
CVE-2020-5726HIGH7.5same product
The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the CTI server on port 8...
CVE-2020-5724HIGH7.5same product
The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websoc...