peter bassill · operator
$ cve CVE-2020-5757 JSON

CVE-2020-5757

9.8
CRITICAL · CVSS 3.1 · EPSS 6.9% (pctl 94)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authenticated remote attacker can bypass command injection mitigations and execute commands as the root user by sending a crafted HTTP POST to the UCM's "New" HTTPS API.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS6.93% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploitnone known
Published2020-07-17
Last modified2026-06-17

Affected (6)

VendorProduct
grandstreamucm6202
grandstreamucm6202 firmware
grandstreamucm6204
grandstreamucm6204 firmware
grandstreamucm6208
grandstreamucm6208 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD