peter bassill · operator
$ cve CVE-2020-5722 JSON

CVE-2020-5722 KEV EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 84.4% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-07-28.

Description

The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. An attacker can use this vulnerability to execute shell commands as root on versions before 1.0.19.20 or inject HTML in password recovery emails in versions before 1.0.20.17.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS84.41% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-89
On CISA KEVyes — remediate by 2022-07-28
Public exploityes
Published2020-03-23
Last modified2026-06-17

CISA KEV

NameGrandstream Networks UCM6200 Series SQL Injection Vulnerability
Added2022-01-28
Due2022-07-28
Vendor / productGrandstream / UCM6200
Ransomware usenone reported

Affected (2)

VendorProduct
grandstreamucm6200
grandstreamucm6200 firmware

Public exploits

SourceTitleDate
exploit-dbUCM6202 1.0.18.13 - Remote Command Injection2020-03-24

References

→ the Explorer  ·  watch your stack  ·  NVD