CVE-2020-5756
Summary
| CVE | CVE-2020-5756 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-07-17 21:15:00 UTC |
| Updated | 2020-07-22 20:43:00 UTC |
| Description | Grandstream GWN7000 firmware version 1.0.9.4 and below allows authenticated remote users to modify the system's crontab via undocumented API. An attacker can use this functionality to execute arbitrary OS commands on the router. |
Risk And Classification
Problem Types: CWE-78
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Grandstream | Gwn7000 | - | All | All | All |
| Hardware | Grandstream | Gwn7000 | - | All | All | All |
| Operating System | Grandstream | Gwn7000 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2020-5756 | Tenable® | https://www.tenable.com/cve/CVE-2020-5756 | www.tenable.com | Exploit, Third Party Advisory |
| MX Player Android App Directory Traversal - Research Advisory | Tenable® | CONFIRM | www.tenable.com | Not Applicable |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.