CVE-2020-5722
Grandstream UCM6200 Series
Published 23 Mar 2020 · updated 17 Jun 2026 · Analyzed
9.8 Critical · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 28 Jan 2022, with a remediation deadline of 28 Jul 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. An attacker can use this vulnerability to execute shell commands as root on versions before 1.0.19.20 or inject HTML in password recovery emails in versions before 1.0.20.17.
References
- packetstormsecurity.com/files/156876/UCM6202-1.0.18.13-Remote-Command-Injection.html · Exploit, Third Party Advisory, VDB Entry
- packetstormsecurity.com/files/165708/Grandstream-UCM62xx-IP-PBX-sendPasswordEmail-Remote-Code-Execution.html · Exploit, Third Party Advisory, VDB Entry
- www.tenable.com/security/research/tra-2020-15 · Exploit, Third Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-5722 · US Government Resource