CVE-2020-5722

Grandstream UCM6200 Series

Published 23 Mar 2020 · updated 17 Jun 2026 · Analyzed

9.8 Critical · CVSS 3.1, NVD

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 28 Jan 2022, with a remediation deadline of 28 Jul 2022 for US federal agencies.

Required action: Apply updates per vendor instructions.

Description

The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. An attacker can use this vulnerability to execute shell commands as root on versions before 1.0.19.20 or inject HTML in password recovery emails in versions before 1.0.20.17.

References