critical·Product Based Web Vulnerabilities·Updated Jan 22, 2026

CVE-2020-5722 Scanner

CVE-2020-5722 Scanner - SQL Injection vulnerability in Grandstream UCM6200

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2020-5722
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. An attacker can use this vulnerability to execute shell commands as root on versions before 1.0.19.20 or inject HTML in password recovery emails in versions before 1.0.20.17.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Grandstream UCM6200 Seriesby n/a
Before 1.0.20.17
Updated Aug 21, 2026View on NVD →
Detail

The Grandstream UCM6200 series are popular IP PBX appliances used by small to medium businesses to ensure seamless communication and connectivity. They offer voice, video, data, and mobility features and are typically deployed in office environments to manage VoIP communications. Businesses rely on these systems to centralize their telephony systems, manage call flows, and integrate with various communication channels. Given their crucial role in operations, securing these devices against vulnerabilities is vital to prevent disruptions. IT administrators often choose Grandstream UCM6200 devices for their advanced features and economical pricing. Updates and proper maintenance of these systems help in mitigating potential security risks.

The SQL Injection vulnerability in the Grandstream UCM6200 series allows unauthenticated attackers to send crafted HTTP requests that can execute shell commands on the device. This critical vulnerability provides a potential path for compromising the entire communication system if exploited. As attackers can execute commands as the root user, the device's integrity is at high risk, potentially leading to unauthorized access and control. Such vulnerabilities highlight the importance of patching and being vigilant against SQL Injection vectors. Attackers utilizing this vulnerability may also inject malicious HTML in emails, exposing users to phishing attacks. This vulnerability demonstrates the critical need for businesses to stay updated on security patches for their communication systems.

The technical aspects of this vulnerability hinge on the ability to manipulate input parameters in crafted HTTP requests directed at vulnerable endpoints. Attackers can use SQL Injection techniques to bypass authentication and gain administrative control through unsanitized input fields. For instance, modifying "user_name=admin" in an HTTP POST request may result in unauthorized access. The vulnerability primarily lies in the lack of input validation in the web interface of the UCM6200 series. It allows attackers to inject arbitrary SQL code, leading to potential command execution. This gap can enable attackers to plant malicious commands or scripts via SQL Injection, jeopardizing the security of the device and the network it is connected to.

If successfully exploited, this vulnerability may lead to severe consequences such as full device compromise and unauthorized root access. Attackers can manipulate device settings, disrupt communication services, intercept sensitive information, or even launch further attacks within the network. The ability to execute shell commands as the root user is particularly dangerous, potentially allowing for backdoor installations or persistent access for malicious use. The email injection aspect could also facilitate phishing attacks, leading to data breaches or further system infections. Businesses failing to address this vulnerability might face downtime, financial loss, and damage to their reputation.

REFERENCES

Solution Advice
  • Update your Grandstream UCM6200 devices to firmware version 1.0.19.20 or later to prevent root command execution via SQL Injection.
  • Regularly monitor and apply security updates from the vendor to safeguard against known vulnerabilities.
  • Implement network segmentation to limit access to the IP PBX to only necessary devices and services.
  • Employ input validation techniques to ensure all user inputs are correctly transformed before execution to prevent SQL Injection.
  • Conduct frequent security assessments and penetration tests to identify and mitigate vulnerabilities in your network infrastructure.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.