CVE-2020-5761 is a CPU exhaustion vulnerability affecting Grandstream HT800 series firmware versions 1.0.17.5 and below, stemming from an infinite loop in the TR-069 service. This high-severity vulnerability (CVSS 7.5) can be triggered remotely by unauthenticated attackers sending a single-character TCP message, leading to a denial of service. While no active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion has been observed, the FAUCET Risk Score indicates a moderate risk. Organizations using affected Grandstream devices should prioritize patching to mitigate this unauthenticated remote denial-of-service risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.0.17.5CPE matchmatch criteria | cpe:2.3:o:grandstream:ht801_firmware:*:*:*:*:*:*:*:* | ||
<= 1.0.17.5CPE matchmatch criteria | cpe:2.3:o:grandstream:ht802_firmware:*:*:*:*:*:*:*:* | ||
<= 1.0.17.5CPE matchmatch criteria | cpe:2.3:o:grandstream:ht812_firmware:*:*:*:*:*:*:*:* | ||
<= 1.0.17.5CPE matchmatch criteria | cpe:2.3:o:grandstream:ht814_firmware:*:*:*:*:*:*:*:* | ||
<= 1.0.17.5CPE matchmatch criteria | cpe:2.3:o:grandstream:ht818_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Grandstream ATA HT800 Series Multiple Vulnerabilities
Jul 29, 2020Grandstream ATA HT800 Series Multiple Vulnerabilities
Jul 29, 2020Grandstream ATA HT800 Series Multiple Vulnerabilities
Jul 29, 2020Grandstream ATA HT800 Series Multiple Vulnerabilities
Jul 29, 2020Grandstream ATA HT800 Series Multiple Vulnerabilities
Jul 29, 2020Grandstream ATA HT800 Series Multiple Vulnerabilities
Jul 29, 2020Grandstream ATA HT800 Series Multiple Vulnerabilities
Jul 29, 2020