ZeroHour

CVE-2020-5722

KEV PoC ×3large

Unauthenticated SQL Injection to Root RCE in Grandstream UCM6200 Series IP PBX

CISA: Grandstream Networks UCM6200 Series SQL Injection Vulnerability

CVSS 3.1
9.8 critical
EPSS
84%p100
Published
()
KEV added
AI analysis

CVE-2020-5722 is an unauthenticated SQL injection (CWE-89) in the HTTP interface of the Grandstream UCM6200 series IP PBX, triggered by sending a crafted HTTP request to the appliance's web service. On firmware versions before 1.0.19.20 an attacker can abuse it to execute arbitrary shell commands as root on the appliance, and on versions before 1.0.20.17 it can also be used to inject HTML into the device's password recovery emails. Any organization running UCM6200-series firmware prior to 1.0.20.17 is affected, with internet-exposed PBX appliances at the greatest risk. The flaw carries a critical CVSS 3.1 score of 9.8 and a top-percentile EPSS probability (84.4%) of exploitation within 30 days; public proof-of-concept exploits exist, CISA added it to the Known Exploited Vulnerabilities catalog on 2022-01-28, and related reporting on the Hoaxcalls botnet expanding its target list is consistent with in-the-wild abuse of these devices.

What to do: Upgrade UCM6200-series firmware to version 1.0.20.17 or later per Grandstream's instructions, which addresses both impact branches; devices on versions before 1.0.19.20 are exposed to unauthenticated root command execution and should be patched immediately. Until patched, restrict the appliance's HTTP interface to trusted management networks and review internet-exposed units for signs of compromise, since CISA has confirmed exploitation.

Affected
Grandstream Networks UCM6200 series IP PBX firmwareall versions before 1.0.20.17 (root shell command execution via the SQL injection in versions before 1.0.19.20; HTML injection in password recovery emails in ve
Estimated exposure
large≈10,000–100,000 internet-exposed UCM6200 appliances (order-of-magnitude estimate) — UCM6200s are on-premises SMB IP PBX appliances whose HTTP interface is routinely left reachable from the internet for remote management, and public internet-wide scan indexes have historically counted Grandstream PBX web portals in the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. An attacker can use this vulnerability to execute shell commands as root on versions before 1.0.19.20 or inject HTML in password recovery emails in versions before 1.0.20.17.

CISA Known Exploited Vulnerability
Affected
Grandstream UCM6200
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
grandstream
Products
ucm6200 firmware
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news