Exploits / Vulnerability Discovered : 2020-03-31 |
Type : webapps |
Platform : hardware
This exploit / vulnerability Grandstream ucm6200 series cti interface user_password sql injection is for educational purposes only and if it is used you will do on your own risk!
[+] Code ...
# Exploit Title: Grandstream UCM6200 Series CTI Interface - 'user_password' SQL Injection
# Date: 2020-03-30
# Exploit Author: Jacob Baines
# Vendor Homepage: http://www.grandstream.com/
# Software Link: http://www.grandstream.com/support/firmware/ucm62xx-official-firmware
# Version: and below
# Tested on: Grandstream UCM6202
# CVE : CVE-2020-5726
# Grandstream UCM6200 Series CTI Interface SQL Injection Password Disclosure
# Advisory: https://www.tenable.com/security/research/tra-2020-17
# Sample output:
# albinolobster@ubuntu:~$ python3 cti_injection.py --rhost
--user lolwat
# [+] Reaching out to
# [+] Password length 9
# [+] The password is LabPass1%