Back
CVE-2020-5722
CRITICAL
CISA KEV
The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. An attacker can use this vulnerability to execute shell commands as root on versions before 1.0.19.20 or inject HTML in password recovery emails in versions before 1.0.20.17.
Published: Mar 23, 2020
Modified: Jun 17, 2026
CWE-89
CWE-89
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| grandstream | ucm6200_firmware | * < 1.0.19.20 |
GitHub Security Advisory GHSA-cggp-723h-vg48
The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote...
References (7)
- http://packetstormsecurity.com/files/156876/UCM6202-1.0.18.13-Remote-Command-Injection.html Exploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/165708/Grandstream-UCM62xx-IP-PBX-sendPasswordEmail-Remote-Code-Execution.html Exploit, Third Party Advisory, VDB Entry
- https://www.tenable.com/security/research/tra-2020-15 Exploit, Third Party Advisory
- http://packetstormsecurity.com/files/156876/UCM6202-1.0.18.13-Remote-Command-Injection.html Exploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/165708/Grandstream-UCM62xx-IP-PBX-sendPasswordEmail-Remote-Code-Execution.html Exploit, Third Party Advisory, VDB Entry
- https://www.tenable.com/security/research/tra-2020-15 Exploit, Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-5722 US Government Resource
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
84.41%
Top 0% most likely to be exploited
Threat Score
94.5 / 100
CISA Known Exploited
Date Added:
2022-01-28
Due Date:
2022-07-28
Required Action:
Apply updates per vendor instructions.
Data Sources
NVD
CISA KEV
EPSS
GitHub