CVE-2020-5762

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
29/07/2020
Last modified:
31/07/2020

Description

Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to a denial of service attack against the TR-069 service. An unauthenticated remote attacker can stop the service due to a NULL pointer dereference in the TR-069 service. This condition is triggered due to mishandling of the HTTP Authentication field.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:grandstream:ht801_firmware:*:*:*:*:*:*:*:* 1.0.17.5 (including)
cpe:2.3:h:grandstream:ht801:-:*:*:*:*:*:*:*
cpe:2.3:o:grandstream:ht802_firmware:*:*:*:*:*:*:*:* 1.0.17.5 (including)
cpe:2.3:h:grandstream:ht802:-:*:*:*:*:*:*:*
cpe:2.3:o:grandstream:ht812_firmware:*:*:*:*:*:*:*:* 1.0.17.5 (including)
cpe:2.3:h:grandstream:ht812:-:*:*:*:*:*:*:*
cpe:2.3:o:grandstream:ht814_firmware:*:*:*:*:*:*:*:* 1.0.17.5 (including)
cpe:2.3:h:grandstream:ht814:-:*:*:*:*:*:*:*
cpe:2.3:o:grandstream:ht818_firmware:*:*:*:*:*:*:*:* 1.0.17.5 (including)
cpe:2.3:h:grandstream:ht818:-:*:*:*:*:*:*:*
cpe:2.3:o:grandstream:ht813_firmware:*:*:*:*:*:*:*:* 1.0.17.5 (including)
cpe:2.3:h:grandstream:ht813:-:*:*:*:*:*:*:*