ZeroHour

CVE-2020-5762

PoC
CVSS 3.1
7.5 high
EPSS
3%p88
Published
()
Modified
Description

Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to a denial of service attack against the TR-069 service. An unauthenticated remote attacker can stop the service due to a NULL pointer dereference in the TR-069 service. This condition is triggered due to mishandling of the HTTP Authentication field.

Vendors
grandstream
Products
ht801 firmware, ht802 firmware, ht812 firmware, ht814 firmware, ht818 firmware, ht813 firmware
Weakness
CWE-476
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.