CVE-2020-5722 is a critical unauthenticated remote SQL injection vulnerability affecting the HTTP interface of Grandstream UCM6200 series IP PBX devices. This flaw allows attackers to execute shell commands as root on older firmware versions or inject HTML into password recovery emails on newer versions. With a CVSS score of 9.8 (CRITICAL) and an EPSS score indicating high exploitability, it poses a significant risk. The vulnerability is actively exploited in the wild, with public exploit code available in Metasploit and ExploitDB, and has garnered substantial community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.19.20CPE matchmatch criteria | cpe:2.3:o:grandstream:ucm6200_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Grandstream UCM62xx SQL Injection
Mar 23, 2020Grandstream UCM62xx SQL Injection
Mar 23, 2020Grandstream UCM62xx SQL Injection
Mar 23, 2020Grandstream UCM62xx SQL Injection
Mar 23, 2020Grandstream UCM62xx SQL Injection
Mar 23, 2020Grandstream UCM62xx SQL Injection
Mar 23, 2020