January 28, 2022 · Applied Cybernetics Group
CVE-2020-5722 — Grandstream UCM6200
Grandstream Networks UCM6200 Series SQL Injection Vulnerability
- Added to KEV
2022-01-28- Federal due date
2022-07-28- Vendor
- Grandstream
- Product
- UCM6200
- EPSS
- 99.8th percentile (score 0.927, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2020-5722
CISA short description
Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. Exploitation can allow for code execution as root.
Required action
Apply updates per vendor instructions.