Loading
Generated remediation guidance and an executive summary. No account required.
Grandstream GWN7000 firmware version 1.0.9.4 and below allows authenticated remote users to modify the system's crontab via undocumented API. An attacker can use this functionality to execute arbitrary OS commands on the router.
Use CWE-489, Grandstream vendor hub and Gwn7000 Firmware product page to widen CVE-2020-5756 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2019-10656 and CVE-2019-10657 for nearby disclosures in the same product family.