CVE-2020-5759
9.8
CRITICAL · CVSS 3.1 · EPSS 3.2% (pctl 88)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via SSH. An authenticated remote attacker can execute commands as the root user by issuing a specially crafted "unset" command.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.2% — more likely to be exploited than 88% of all CVEs |
| Weakness | CWE-78 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2020-07-17 |
| Last modified | 2026-06-17 |
Affected (6)
| Vendor | Product |
|---|---|
| grandstream | ucm6202 |
| grandstream | ucm6202 firmware |
| grandstream | ucm6204 |
| grandstream | ucm6204 firmware |
| grandstream | ucm6208 |
| grandstream | ucm6208 firmware |
References
→ the Explorer · watch your stack · NVD