9

CVE-2020-25217

Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allows Command Injection as root in its administrative web interface.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GrandstreamGrp2612 Firmware Version1.0.3.6
   GrandstreamGrp2612 Version-
GrandstreamGrp2612p Firmware Version1.0.3.6
   GrandstreamGrp2612p Version-
GrandstreamGrp2612w Firmware Version1.0.3.6
   GrandstreamGrp2612w Version-
GrandstreamGrp2613 Firmware Version1.0.3.6
   GrandstreamGrp2613 Version-
GrandstreamGrp2614 Firmware Version1.0.3.6
   GrandstreamGrp2614 Version-
GrandstreamGrp2615 Firmware Version1.0.3.6
   GrandstreamGrp2615 Version-
GrandstreamGrp2616 Firmware Version1.0.3.6
   GrandstreamGrp2616 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.09% 0.863
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 9 8 10
AV:N/AC:L/Au:S/C:C/I:C/A:C
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.