CVE detail
CVE-2020-5761 — CVE-2020-5761
Published 2020-07-29 · Modified 2026-06-17 · Vendor grandstream · Product ht801_firmware · Source nvd
HIGH
severity
CVSS-derived band
0.0409
EPSS probability
exploitation probability, 30d
90.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to CPU exhaustion due to an infinite loop in the TR-069 service. Unauthenticated remote attackers can trigger this case by sending a one character TCP message to the TR-069 service.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References