SQL Injection Vulnerability in Grandstream UCM6200 Series by Grandstream
CVE-2020-5725
5.9MEDIUM
What is CVE-2020-5725?
The Grandstream UCM6200 series devices, prior to version 1.0.20.22, are susceptible to an SQL injection vulnerability via the websockify endpoint in the HTTP server. This flaw allows a remote, unauthenticated attacker to exploit the login mechanism by transmitting a specially crafted username. Through sophisticated timing attacks, the attacker may successfully retrieve user passwords, potentially leading to unauthorized access and manipulation of sensitive data.
Affected Version(s)
Grandstream UCM6200 series 1.0.20.20 and below