CVE-2024-0840
The Grandstream UCM Series IP PBX before firmware version 1.0.20.52 is affected by a parameter injection vulnerability in the HTTP interface. A remote and authenticated attacker can execute arbitrary code by sending a crafted HTTP request. Authentication may be possible using a default user and password. Affected models are the UCM6202, UCM6204, UCM6208, and UCM6510.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.88%
- CWE
- CWE-141
- Published
- 2024-04-29
- Last modified
- 2026-03-13
Affected products
- Grandstream UCM Series
Weakness type
Related vulnerabilities
- CVE-2026-66323 — Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
- CVE-2026-19594 — Path Traversal and HTTP Parameter Pollution in Snowflake Python API (snowflake.core) Allow Confused-Deputy Privilege Escalation
- CVE-2026-20200 — Cisco Integrated Management Controller Argument Injection and Remote Code Execution Vulnerability
- CVE-2026-56813 — Cookie attribute injection in Plug.Conn.Cookies.encode/2
- CVE-2025-20338 — A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker...
- CVE-2025-31329 — Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform
- CVE-2022-41665 — A vulnerability has been identified in SICAM P850 (7KG8500-0AA00-0AA0) (All versions < V3.10),...
- CVE-2022-29873 — A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not...