9
CVSSv2

CVE-2020-5739

Published: 14/04/2020 Updated: 14/04/2020
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker adds an OpenVPN up script to the phone's VPN settings via the "Additional Settings" field in the web interface. When the VPN's connection is established, the user defined script is executed with root privileges.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

grandstream gxp1610_firmware

grandstream gxp1615_firmware

grandstream gxp1620_firmware

grandstream gxp1625_firmware

grandstream gxp1628_firmware

grandstream gxp1630_firmware