Beveiligingsadvies

CVE-2020-5739

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2020-04-14 13:48:50
Laatst bijgewerkt 2024-08-04 08:39:25
Toegewezen door tenable
CVSS-score geen score
Status PUBLISHED

Beschrijving

Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker adds an OpenVPN up script to the phone's VPN settings via the "Additional Settings" field in the web interface. When the VPN's connection is established, the user defined script is executed with root privileges.