← Back

CVE-2020-5756

nvd nist
Published: Jul 17, 2020Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

Grandstream GWN7000 firmware version 1.0.9.4 and below allows authenticated remote users to modify the system's crontab via undocumented API. An attacker can use this functionality to execute arbitrary OS commands on the router.

Affected (1)

1 product
Gwn7000 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.0.9.4
Running on/withPlatform Versions
Grandstream
Gwn7000
All versions

References (3)

Source: vulnreport@tenable.com
Not Applicable
Source: nvd@nist.gov
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Not Applicable

Timeline

No history available yet.