Grandstream UCM62xx IP PBX sendPasswordEmail Remote Code Execution
Posted by deepcore on January 26, 2022 – 12:11 pm
This Metasploit module exploits an unauthenticated SQL injection vulnerability and a command injection vulnerability affecting the Grandstream UCM62xx IP PBX series of devices. The vulnerabilities allow an unauthenticated remote attacker to execute commands as root.
Post a reply
You must be logged in to post a comment.