SQL Injection Vulnerability in Grandstream UCM6200 Series by Grandstream
CVE-2020-5725

5.9MEDIUM

Key Information:

Vendor
CVE Published:
30 March 2020

What is CVE-2020-5725?

The Grandstream UCM6200 series devices, prior to version 1.0.20.22, are susceptible to an SQL injection vulnerability via the websockify endpoint in the HTTP server. This flaw allows a remote, unauthenticated attacker to exploit the login mechanism by transmitting a specially crafted username. Through sophisticated timing attacks, the attacker may successfully retrieve user passwords, potentially leading to unauthorized access and manipulation of sensitive data.

Affected Version(s)

Grandstream UCM6200 series 1.0.20.20 and below

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.