Vulnerability Description
Grandstream GWN7000 firmware version 1.0.9.4 and below allows authenticated remote users to modify the system's crontab via undocumented API. An attacker can use this functionality to execute arbitrary OS commands on the router.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Grandstream | Gwn7000 Firmware | <= 1.0.9.4 |
| Grandstream | Gwn7000 | - |
Related Weaknesses (CWE)
References
- https://www.tenable.com/security/research/tra-2020-41Not Applicable
- https://www.tenable.com/cve/CVE-2020-5756ExploitThird Party Advisory
- https://www.tenable.com/security/research/tra-2020-41Not Applicable
FAQ
What is CVE-2020-5756?
CVE-2020-5756 is a vulnerability with a CVSS score of 8.8 (HIGH). Grandstream GWN7000 firmware version 1.0.9.4 and below allows authenticated remote users to modify the system's crontab via undocumented API. An attacker can use this functionality to execute arbitrar...
How severe is CVE-2020-5756?
CVE-2020-5756 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-5756?
Check the references section above for vendor advisories and patch information. Affected products include: Grandstream Gwn7000 Firmware, Grandstream Gwn7000.