Show filters
52 Total Results
Displaying 11-20 of 52
Sort by:
Attacker Value
Unknown
CVE-2020-5761
Disclosure Date: July 29, 2020 (last updated February 21, 2025)
Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to CPU exhaustion due to an infinite loop in the TR-069 service. Unauthenticated remote attackers can trigger this case by sending a one character TCP message to the TR-069 service.
0
Attacker Value
Unknown
CVE-2020-5762
Disclosure Date: July 29, 2020 (last updated February 21, 2025)
Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to a denial of service attack against the TR-069 service. An unauthenticated remote attacker can stop the service due to a NULL pointer dereference in the TR-069 service. This condition is triggered due to mishandling of the HTTP Authentication field.
0
Attacker Value
Unknown
CVE-2020-5759
Disclosure Date: July 17, 2020 (last updated February 21, 2025)
Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via SSH. An authenticated remote attacker can execute commands as the root user by issuing a specially crafted "unset" command.
0
Attacker Value
Unknown
CVE-2020-5758
Disclosure Date: July 17, 2020 (last updated February 21, 2025)
Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authenticated remote attacker can execute commands as the root user by sending a crafted HTTP GET to the UCM's "Old" HTTPS API.
0
Attacker Value
Unknown
CVE-2020-5756
Disclosure Date: July 17, 2020 (last updated February 21, 2025)
Grandstream GWN7000 firmware version 1.0.9.4 and below allows authenticated remote users to modify the system's crontab via undocumented API. An attacker can use this functionality to execute arbitrary OS commands on the router.
0
Attacker Value
Unknown
CVE-2020-5757
Disclosure Date: July 17, 2020 (last updated February 21, 2025)
Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authenticated remote attacker can bypass command injection mitigations and execute commands as the root user by sending a crafted HTTP POST to the UCM's "New" HTTPS API.
0
Attacker Value
Unknown
CVE-2020-5739
Disclosure Date: April 14, 2020 (last updated February 21, 2025)
Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker adds an OpenVPN up script to the phone's VPN settings via the "Additional Settings" field in the web interface. When the VPN's connection is established, the user defined script is executed with root privileges.
0
Attacker Value
Unknown
CVE-2020-5738
Disclosure Date: April 14, 2020 (last updated February 21, 2025)
Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker uploads a specially crafted tar file to the HTTP /cgi-bin/upload_vpntar interface.
0
Attacker Value
Unknown
CVE-2020-5725
Disclosure Date: March 30, 2020 (last updated February 21, 2025)
The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpoint. A remote unauthenticated attacker can invoke the login action with a crafted username and, through the use of timing attacks, can discover user passwords.
0
Attacker Value
Unknown
CVE-2020-5723
Disclosure Date: March 30, 2020 (last updated February 21, 2025)
The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database. This could allow an attacker to retrieve all passwords and possibly gain elevated privileges.
0