SQL Injection Vulnerability in Grandstream UCM6200 Series CTI Server
CVE-2020-5726
7.5HIGH
What is CVE-2020-5726?
The Grandstream UCM6200 series products prior to version 1.0.20.22 are susceptible to an SQL injection vulnerability through the CTI server operating on port 8888. This flaw allows unauthenticated remote attackers to execute specially crafted requests, triggering the challenge action and potentially exposing sensitive user passwords. Organizations utilizing these devices must ensure they are on the latest firmware to mitigate risks associated with this vulnerability.
Affected Version(s)
Grandstream UCM6200 series 1.0.20.20 and below