CVE-2020-5722
The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. An attacker can use this vulnerability to execute shell commands as root on versions before 1.0.19.20 or inject HTML in password recovery emails in versions before 1.0.20.17.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Base score: 9.8
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 84%
- Percentile among all scored CVEs: 100
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
CISA KEV — actively exploited
- Added to catalog: 1/28/2022
- Remediation due date: 7/28/2022
- Known ransomware use: Unknown
💥 Public exploits
Exploit code or detection templates are publicly available. This is not the same as confirmed active exploitation (KEV), but it raises the risk: patch with priority.
- Metasploit module (reliable, widely available exploit) · Grandstream UCM62xx IP PBX sendPasswordEmail RCE
- Published on Exploit-DB · UCM6202 1.0.18.13 - Remote Command Injection (3/24/2020)
- Nuclei template (automated mass detection) · Grandstream UCM6200 - SQL Injection
🎯 ATT&CK techniques
How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.
- Exploitation
T1190Exploit Public-Facing Applicationinitial access95 % - Secondary impact
T1005Data from Local Systemcollection85 % - Secondary impact
T1565.001Stored Data Manipulationimpact80 %
SQL injection remota sin autenticación (CWE-89) en interfaz HTTP permite ejecución de comandos shell como root. Vector CVSS AV:N/PR:N/UI:N confirma explotabilidad remota directa (T1190). Impactos: ejecución de comandos (T1059.007), lectura de datos SQL (T1005), modificación de correos de recuperació
Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.
🛡️ ATT&CK mitigations that cover these techniques
Affected technologies (1)
CWEs
- CWE-89
- CWE-89
References
- http://packetstormsecurity.com/files/156876/UCM6202-1.0.18.13-Remote-Command-Injection.html
- http://packetstormsecurity.com/files/165708/Grandstream-UCM62xx-IP-PBX-sendPasswordEmail-Remote-Code-Execution.html
- https://www.tenable.com/security/research/tra-2020-15
- http://packetstormsecurity.com/files/156876/UCM6202-1.0.18.13-Remote-Command-Injection.html
- http://packetstormsecurity.com/files/165708/Grandstream-UCM62xx-IP-PBX-sendPasswordEmail-Remote-Code-Execution.html
- https://www.tenable.com/security/research/tra-2020-15
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-5722
Raw JSON (NVD)
Show
{
"id": "CVE-2020-5722",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2020-5722",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "active"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-02-06T20:27:25.790617Z"
}
}
],
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 10,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
},
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "vulnreport@tenable.com",
"affectedData": [
{
"vendor": "n/a",
"product": "Grandstream UCM6200 Series",
"versions": [
{
"status": "affected",
"version": "Before 1.0.20.17"
}
]
}
]
}
],
"published": "2020-03-23T20:15:12.043",
"references": [
{
"url": "http://packetstormsecurity.com/files/156876/UCM6202-1.0.18.13-Remote-Command-Injection.html",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"source": "vulnreport@tenable.com"
},
{
"url": "http://packetstormsecurity.com/files/165708/Grandstream-UCM62xx-IP-PBX-sendPasswordEmail-Remote-Code-Execution.html",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"source": "vulnreport@tenable.com"
},
{
"url": "https://www.tenable.com/security/research/tra-2020-15",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "vulnreport@tenable.com"
},
{
"url": "http://packetstormsecurity.com/files/156876/UCM6202-1.0.18.13-Remote-Command-Injection.html",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://packetstormsecurity.com/files/165708/Grandstream-UCM62xx-IP-PBX-sendPasswordEmail-Remote-Code-Execution.html",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.tenable.com/security/research/tra-2020-15",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-5722",
"tags": [
"US Government Resource"
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-89"
}
]
},
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"description": [
{
"lang": "en",
"value": "CWE-89"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. An attacker can use this vulnerability to execute shell commands as root on versions before 1.0.19.20 or inject HTML in password recovery emails in versions before 1.0.20.17."
},
{
"lang": "es",
"value": "La interfaz HTTP de la serie Grandstream UCM6200 es vulnerable a una inyección SQL remota no autenticada por medio de una petición HTTP diseñada. Un atacante puede usar esta vulnerabilidad para ejecutar comandos de shell como root en versiones anteriores a 1.0.19.20 o inyectar HTML en correos electrónicos de recuperación de contraseña en versiones anteriores a 1.0.20.17."
}
],
"lastModified": "2026-06-17T03:22:06.003",
"cisaActionDue": "2022-07-28",
"cisaExploitAdd": "2022-01-28",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:grandstream:ucm6200_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "98FF035C-153C-497E-B889-6C7D836769EA",
"versionEndExcluding": "1.0.19.20"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:grandstream:ucm6200:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "F9F3E859-0FC6-44E6-909E-4312CBA03032"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "vulnreport@tenable.com",
"cisaRequiredAction": "Apply updates per vendor instructions.",
"cisaVulnerabilityName": "Grandstream Networks UCM6200 Series SQL Injection Vulnerability"
}