Grandstream GWN7000 firmware version 1.0.9.4 and below allows authenticated remote users to modify the system's crontab via undocumented API. An attacker can use this functionality to execute arbitrary OS commands on the router.
References
Link | Resource |
---|---|
https://www.tenable.com/security/research/tra-2020-41 | Not Applicable |
https://www.tenable.com/cve/CVE-2020-5756 | Exploit Third Party Advisory |
https://www.tenable.com/security/research/tra-2020-41 | Not Applicable |
Configurations
Configuration 1 (hide)
AND |
|
History
No history.
Information
Published : 2020-07-17 21:15
Updated : 2024-11-21 05:34
NVD link : CVE-2020-5756
Mitre link : CVE-2020-5756
CVE.ORG link : CVE-2020-5756
JSON object : View
Products Affected
grandstream
- gwn7000_firmware
- gwn7000