EXPOSURES › CVE-2020-5722
CVE-2020-5722
HIGH ⌖ ON CISA KEV · EXPLOITEDGrandstream UCM6200 VoIP devices suffered an unauthenticated remote SQL injection allowing root code execution.
An unauthenticated SQL injection flaw in Grandstream UCM6200 VoIP devices allowed attackers to execute arbitrary code as root via crafted HTTP requests. DIB organizations must care because this unpatched vulnerability was actively exploited in the wild, enabling full device compromise and potential network pivoting. Organizations should immediately patch or replace affected hardware and assume breach for any unpatched devices.
Shame score — A critical, unauthenticated SQL injection allowing root code execution remained unpatched and was actively exploited in the wild, representing a severe negligence failure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. Exploitation can allow for code execution as root.