Grandstream Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Grandstream products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

1

In CISA KEV

1

Beyond CISA KEV

0

Sensor Observed

0

Virtual Patch Available

0

Grandstream KEVs Added by Year

Loading...

1 Grandstream KEV added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2020-5722

The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. An attacker...

Confirmed In CISA 28 Jan 2022

Common Vulnerability Classes (CWE)

  • CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology