LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-5722: Grandstream Networks UCM6200 Series SQL Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jan 28, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jul 28, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-5722 to its Known Exploited Vulnerabilities catalog on Jan 28, 2022, with a federal patch deadline of Jul 28, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. Exploitation can allow for code execution as root.

CVE-2020-5722 is an unauthenticated remote SQL injection vulnerability in the Grandstream UCM6200 series. An attacker who can reach the device over the network can send a crafted HTTP request that abuses the flaw, and successful exploitation can lead to code execution as root. That combination makes the issue material for any environment where these IP-PBX / unified-communications appliances are exposed or poorly segmented.

Public detail is limited to the product family, the CWE class, and the high-level impact described by CISA. Confirm exact fixed versions, affected firmware builds, and remediation steps against the vendor advisory before acting.

How it works

The weakness is CWE-89 (SQL injection). The UCM6200 series accepts HTTP requests that ultimately influence database queries. When user-controlled input is not properly parameterized or sanitized, an attacker can alter the intended SQL statement.

Because the vulnerability is reachable without authentication, a remote attacker only needs network access to the management or service interface that processes the vulnerable request. In this class of flaw, injected SQL can often be leveraged to read or modify data, and—when the database engine or surrounding application logic permits—it can be chained to operating-system command execution. CISA notes that exploitation of this particular issue can allow code execution as root. Exact request parameters, endpoints, and payload mechanics are not provided here; treat any public proof-of-concept with caution and validate solely against the vendor’s advisory.

Am I affected? How to find it in your systems

Grandstream UCM6200 devices are typically deployed as on-premises unified-communications / IP-PBX appliances. They may sit on voice VLANs, in DMZs, or occasionally on internet-facing addresses for remote administration or SIP services.

How to remediate

Patch first. Apply the firmware update supplied by Grandstream for the UCM6200 series exactly as described in the vendor advisory. CISA’s required action is to apply updates per vendor instructions.

If you can't patch immediately

Implement compensating controls while you arrange the upgrade:

These measures reduce likelihood and impact but do not eliminate the vulnerability. Plan to patch as soon as possible.

If your data may have been exposed

Actively exploited vulnerabilities of this severity can lead to full device compromise and subsequent lateral movement or data theft. Known ransomware use of CVE-2020-5722 is not documented, yet root-level access still warrants treating the appliance and any credentials or call-detail records it holds as potentially exposed. Rotate credentials that were stored on or used by the device, review call and configuration logs for unauthorized changes, and follow your incident-response process. You can also run a free exposure scan of your email addresses against known breach data sets to see whether associated accounts have appeared in prior breaches.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedGrandstream · UCM6200
WeaknessCWE-89
Added to CISA KEVJan 28, 2022
Federal patch deadlineJul 28, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities