Loading
Generated remediation guidance and an executive summary. No account required.
Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the backupUCMConfig file-backup parameter to the /cgi? URI.
Use CWE-78, Grandstream vendor hub and Ucm6204 Firmware product page to widen CVE-2019-10662 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2020-5759, CVE-2020-5757 and CVE-2020-5723 for nearby disclosures in the same product family.