PT-2020-18677 · Grandstream · Grandstream Gwn7000
David Wells
·
Published
2020-07-17
·
Updated
2020-07-22
·
CVE-2020-5756
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Grandstream GWN7000 firmware version 1.0.9.4 and below
Description
The issue allows authenticated remote users to modify the system's crontab via an undocumented API, enabling the execution of arbitrary OS commands on the router.
Recommendations
For Grandstream GWN7000 firmware version 1.0.9.4 and below, update to a version above 1.0.9.4 to resolve the issue. As a temporary workaround, consider restricting access to the undocumented API until a patch is available.
Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Grandstream Gwn7000