peter bassill · operator
$ cve CVE-2020-5726 JSON

CVE-2020-5726 EXPLOIT

7.5
HIGH · CVSS 3.1 · EPSS 4.3% (pctl 91)

Patch early

A public exploit exists.

Description

The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the CTI server on port 8888. A remote unauthenticated attacker can invoke the challenge action with a crafted username and discover user passwords.

Scoring

CVSS7.5 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS4.33% — more likely to be exploited than 91% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2020-03-30
Last modified2026-06-17

Affected (6)

VendorProduct
grandstreamucm6202
grandstreamucm6202 firmware
grandstreamucm6204
grandstreamucm6204 firmware
grandstreamucm6208
grandstreamucm6208 firmware

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD