Critical severity9.8NVD Advisory· Published Jul 17, 2020· Updated Jun 17, 2026
CVE-2020-5757
CVE-2020-5757
Description
Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authenticated remote attacker can bypass command injection mitigations and execute commands as the root user by sending a crafted HTTP POST to the UCM's "New" HTTPS API.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- cpe:2.3:o:grandstream:ucm6202_firmware:*:*:*:*:*:*:*:*Range: <=1.0.20.23
- cpe:2.3:o:grandstream:ucm6204_firmware:*:*:*:*:*:*:*:*Range: <=1.0.20.23
- cpe:2.3:o:grandstream:ucm6208_firmware:*:*:*:*:*:*:*:*Range: <=1.0.20.23
- Range: <=1.0.20.23
Patches
Vulnerability mechanics
References
2- www.tenable.com/cve/CVE-2020-5757nvdThird Party Advisory
- www.tenable.com/security/research/tra-2020-42nvdNot Applicable
News mentions
0No linked articles in our index yet.