CVE-2020-5763
29.07.2020, 19:15
Grandstream HT800 series firmware version 1.0.17.5 and below contain a backdoor in the SSH service. An authenticated remote attacker can obtain a root shell by correctly answering a challenge prompt.Enginsight
Vendor | Product | Version |
---|---|---|
grandstream | ht801_firmware | 𝑥 ≤ 1.0.17.5 |
grandstream | ht802_firmware | 𝑥 ≤ 1.0.17.5 |
grandstream | ht812_firmware | 𝑥 ≤ 1.0.17.5 |
grandstream | ht814_firmware | 𝑥 ≤ 1.0.17.5 |
grandstream | ht818_firmware | 𝑥 ≤ 1.0.17.5 |
grandstream | ht813_firmware | 𝑥 ≤ 1.0.17.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-489 - Active Debug CodeThe application is deployed to unauthorized actors with debugging code still enabled or active, which can create unintended entry points or expose sensitive information.
- CWE-326 - Inadequate Encryption StrengthThe software stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.