CVE-2020-5759

CRITICAL

Grandstream UCM6200 <1.0.20.23 - Command Injection

Title source: llm
STIX 2.1

Description

Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via SSH. An authenticated remote attacker can execute commands as the root user by issuing a specially crafted "unset" command.

References (2)

Core 2
Core References
Not Applicable x_refsource_confirm
https://www.tenable.com/security/research/tra-2020-42

Scores

CVSS v3 9.8
EPSS 0.0320
EPSS Percentile 86.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (3)
grandstream/ucm6202_firmware < 1.0.20.23
grandstream/ucm6204_firmware < 1.0.20.23
grandstream/ucm6208_firmware < 1.0.20.23
Published Jul 17, 2020
Tracked Since Feb 18, 2026