← Back

Ucm6200 Firmware

ucm6200_firmware

Vendor: Grandstream • 1 CVE

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Grandstream
1Ucm6200 Firmware
Jun 17, 2026
Mar 23, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. An attacker can use this vulnerability to execute shell commands as root on versions...Show more
The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. An attacker can use this vulnerability to execute shell commands as root on versions before 1.0.19.20 or inject HTML in password recovery emails in versions before 1.0.20.17.Show less