Loading
Generated remediation guidance and an executive summary. No account required.
The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. An attacker can use this vulnerability to execute shell commands as root on versions before 1.0.19.20 or inject HTML in password recovery emails in versions before 1.0.20.17.
Use CWE-89, Grandstream vendor hub and Ucm6200 Firmware product page to widen CVE-2020-5722 into its surrounding weakness, vendor, and product context.