Vulnerability record · CVE-2020-5722 · published 23 March 2020
CVE-2020-5722: Grandstream UCM6200 HTTP interface unauthenticated SQL injection
Grandstream · Ucm6200 Firmware
The HTTP interface of the Grandstream UCM6200 series is vulnerable to unauthenticated remote SQL injection through crafted HTTP requests. On versions before 1.0.19.20 an attacker can execute shell commands as root, and before 1.0.20.17 can inject HTML into password recovery emails. It matters because the flaw is remotely reachable without credentials and can yield full root compromise of the PBX appliance.
Description
The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. An attacker can use this vulnerability to execute shell commands as root on versions before 1.0.19.20 or inject HTML in password recovery emails in versions before 1.0.20.17.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable SQL injection leading to root command execution, with KEV listing, public exploit references and very high EPSS probability.
What it is
The HTTP interface of the Grandstream UCM6200 series is vulnerable to unauthenticated remote SQL injection through crafted HTTP requests. On versions before 1.0.19.20 an attacker can execute shell commands as root, and before 1.0.20.17 can inject HTML into password recovery emails. It matters because the flaw is remotely reachable without credentials and can yield full root compromise of the PBX appliance.
Impact
An attacker gains root-level command execution on the affected appliance, allowing full control of the device and any data or telephony configuration it holds. In the alternate path, injected HTML in password recovery emails can be used to attack mail recipients.
Attack surface
Reached over the network through the UCM6200 HTTP interface; the CVSS vector shows no privileges required and no user interaction. No authentication is needed to send the crafted request.
Exploitation
CVE-2020-5722 is listed in CISA KEV with a 2022-01-28 addition date, and EPSS shows a 30-day probability of 0.84406 (percentile 0.99686). Multiple references are tagged Exploit, indicating public exploit material exists; KEV notes no known ransomware campaign use.
What to do
- Apply the vendor firmware updates that address the flaw (at minimum 1.0.19.20 for the command execution path and 1.0.20.17 for the email injection path).
- Restrict network access to the UCM6200 HTTP interface to trusted management networks and block exposure to the internet.
- Place the appliance behind a firewall or reverse proxy that filters malformed or injection-style HTTP requests where feasible.
- Monitor vendor advisories and CISA KEV guidance for this CVE and confirm remediation status.
- Rotate credentials and review appliance configuration for signs of tampering after any suspected exposure.
Detection
- Inspect HTTP request logs for SQL injection patterns (quotes, UNION, stacked queries, comment sequences) against UCM6200 endpoints.
- Alert on unexpected outbound connections or shell activity originating from the PBX appliance.
- Monitor for anomalous password recovery email generation or content changes tied to the sendPasswordEmail functionality.
- Correlate appliance firmware version against the fixed releases to identify unpatched UCM6200 devices.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-5722 to the Known Exploited Vulnerabilities catalog on 28 January 2022 as "Grandstream Networks UCM6200 Series SQL Injection Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 28 July 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/156876/UCM6202-1.0.18.13-Remote-Command-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/165708/Grandstream-UCM62xx-IP-PBX-sendPasswordEmail-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.tenable.com/security/research/tra-2020-15 | ExploitThird Party Advisory |
| http://packetstormsecurity.com/files/156876/UCM6202-1.0.18.13-Remote-Command-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/165708/Grandstream-UCM62xx-IP-PBX-sendPasswordEmail-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.tenable.com/security/research/tra-2020-15 | ExploitThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-5722 | US Government Resource |
Track CVE-2020-5722 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-5722), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.