7.5
CVSSv3

CVE-2020-5726

Published: 30/03/2020 Updated: 31/03/2020
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The Grandstream UCM6200 series prior to 1.0.20.22 is vulnerable to an SQL injection via the CTI server on port 8888. A remote unauthenticated attacker can invoke the challenge action with a crafted username and discover user passwords.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

grandstream ucm6202 firmware

grandstream ucm6204 firmware

grandstream ucm6208 firmware

Exploits

Grandstream UCM6200 Series CTI Interface versions 102020 and below suffer from a remote SQL injection vulnerability ...