PT-2020-18682 · Grandstream · Grandstream Ht800

Published

2020-07-29

·

Updated

2020-07-31

·

CVE-2020-5761

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Grandstream HT800 series firmware version 1.0.17.5 and below
Description The issue is related to CPU exhaustion due to an infinite loop in the TR-069 service. Unauthenticated remote attackers can trigger this by sending a one character TCP message to the TR-069 service.
Recommendations For Grandstream HT800 series firmware version 1.0.17.5 and below, consider disabling the TR-069 service until a patch is available to prevent CPU exhaustion attacks.

Exploit

Fix

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-5761

Affected Products

Grandstream Ht800