Back

HIGH

Grandstream UCM Series IP PBX HTTP Parameter Injection

Published Apr 29, 2024

Description

The Grandstream UCM Series IP PBX before firmware version 1.0.20.52 is affected by a parameter injection vulnerability in the HTTP interface. A remote and authenticated attacker can execute arbitrary code by sending a crafted HTTP request. Authentication may be possible using a default user and password. Affected models are the UCM6202, UCM6204, UCM6208, and UCM6510.

Affected products

Remediation

Vendor solution

Upgrade to firmware version 1.0.20.52 or later. Ensure the web interface is not exposed to the internet.

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Apr 29, 2024
Updated Aug 1, 2024
Reserved Jan 23, 2024
CISA Vulnrichment
Updated May 1, 2024
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner n/a
Published n/a
Updated n/a
Exploited since n/a
Link n/a