PT-2020-18677 · Grandstream · Grandstream Gwn7000

David Wells

·

Published

2020-07-17

·

Updated

2020-07-22

·

CVE-2020-5756

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Grandstream GWN7000 firmware version 1.0.9.4 and below
Description The issue allows authenticated remote users to modify the system's crontab via an undocumented API, enabling the execution of arbitrary OS commands on the router.
Recommendations For Grandstream GWN7000 firmware version 1.0.9.4 and below, update to a version above 1.0.9.4 to resolve the issue. As a temporary workaround, consider restricting access to the undocumented API until a patch is available.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-5756

Affected Products

Grandstream Gwn7000