Grandstream GWN7000 firmware version 1.0.9.4 and below allows authenticated remote users to modify the system's crontab via undocumented API. An attacker can use this functionality to execute arbitrary OS commands on the router.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: tenable
Published: 2020-07-17T20:16:27
Updated: 2024-08-04T08:39:25.704Z
Reserved: 2020-01-06T00:00:00
Link: CVE-2020-5756
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-07-17T21:15:13.607
Modified: 2024-11-21T05:34:32.783
Link: CVE-2020-5756
Redhat
No data.