← Vulnerability feed

Vulnerability record · CVE-2019-10662 · published 30 March 2019

CVE-2019-10662: Grandstream ucm6204 firmware os command injection vulnerability

Grandstream · Ucm6204 Firmware

Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the backupUCMConfig file-backup parameter to the /cgi? URI.

8.8 CVSS 3.1 High EPSS 44% · top 1.3% CWE-78 · OS command injection
8.8CVSS 3.1 base score, v2 9.0
44%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the backupUCMConfig file-backup parameter to the /cgi? URI.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-10662 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-5757Grandstream ucm6202 firmware os command injection vulnerabilityGrandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authenticated remote attacker can …EPSS 6.9%9.8CVE-2020-5759Grandstream ucm6202 firmware os command injection vulnerabilityGrandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via SSH. An authenticated remote attacker can e…EPSS 3.2%9.8CVE-2020-5723Grandstream ucm6202 firmware cleartext storage of sensitive data vulnerabilityThe UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database. This could allow an attacker to retrieve all password…EPSS 5.9%8.8CVE-2020-5758Grandstream ucm6202 firmware os command injection vulnerabilityGrandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authenticated remote attacker can …EPSS 4.4%8.8CVE-2019-10663Grandstream ucm6204 firmware sql injection vulnerabilityGrandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to conduct SQL injection attacks via the sord parameter in a listCodebl…EPSS 28%7.5CVE-2020-5724Grandstream ucm6202 firmware sql injection vulnerabilityThe Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpoint. A remote unauthenticated…EPSS 12%7.5CVE-2020-5726Grandstream ucm6202 firmware sql injection vulnerabilityThe Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the CTI server on port 8888. A remote unauthenticated attacker …EPSS 4.3%5.9CVE-2020-5725Grandstream ucm6202 firmware sql injection vulnerabilityThe Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpoint. A remote unauthenticated…EPSS 1.8%

Source: NIST National Vulnerability Database (record CVE-2019-10662), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.