CVE Tools

UCM6204 Firmware

9 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for UCM6204 Firmware, a product in the communications space. Use it to gauge the current risk picture and drill into individual advisories.

UCM6204 Firmware CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
UCM6204 Firmware CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 9 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical333%
  • High556%
  • Medium111%

Latest CVEs

The 9 most recently published vulnerabilities affecting UCM6204 Firmware.

  1. CVE-2020-5759Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via SSH. An authenticated remote attacker can execute commands as the root user by issuing a sp...9.8
  2. CVE-2020-5758Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authenticated remote attacker can execute commands as the root user by sending a c...8.8
  3. CVE-2020-5757Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authenticated remote attacker can bypass command injection mitigations and execute...9.8
  4. CVE-2020-5726The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the CTI server on port 8888. A remote unauthenticated attacker can invoke the challenge action with a crafted u...7.5
  5. CVE-2020-5725The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpoint. A remote unauthenticated attacker can invoke the login action with a cra...5.9
  6. CVE-2020-5724The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpoint. A remote unauthenticated attacker can invoke the challenge action with a...7.5
  7. CVE-2020-5723The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database. This could allow an attacker to retrieve all passwords and possibly gain elevated privileges.9.8
  8. CVE-2019-10663Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to conduct SQL injection attacks via the sord parameter in a listCodeblueGroup API call to the /cgi? URI.8.8
  9. CVE-2019-10662Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the backupUCMConfig file-backup parameter to the /cgi? URI.8.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store