CVE-2020-5722 KEV EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 84.4% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2022-07-28.
Description
The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. An attacker can use this vulnerability to execute shell commands as root on versions before 1.0.19.20 or inject HTML in password recovery emails in versions before 1.0.20.17.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 84.41% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | yes — remediate by 2022-07-28 |
| Public exploit | yes |
| Published | 2020-03-23 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Grandstream Networks UCM6200 Series SQL Injection Vulnerability |
|---|---|
| Added | 2022-01-28 |
| Due | 2022-07-28 |
| Vendor / product | Grandstream / UCM6200 |
| Ransomware use | none reported |
Affected (2)
| Vendor | Product |
|---|---|
| grandstream | ucm6200 |
| grandstream | ucm6200 firmware |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | UCM6202 1.0.18.13 - Remote Command Injection | 2020-03-24 |
References
- http://packetstormsecurity.com/files/156876/UCM6202-1.0.18.13-Remote-Command-Injection.html
- http://packetstormsecurity.com/files/165708/Grandstream-UCM62xx-IP-PBX-sendPasswordEmail-Remote-Code-Execution.html
- https://www.tenable.com/security/research/tra-2020-15
- http://packetstormsecurity.com/files/156876/UCM6202-1.0.18.13-Remote-Command-Injection.html
- http://packetstormsecurity.com/files/165708/Grandstream-UCM62xx-IP-PBX-sendPasswordEmail-Remote-Code-Execution.html
- https://www.tenable.com/security/research/tra-2020-15
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-5722
→ the Explorer · watch your stack · NVD