ZeroHour

CVE-2020-10181

KEV PoC ×3niche

CSRF in Sumavision EMR Lets Attackers Create Rogue Administrator Accounts

CISA: Sumavision EMR Cross-Site Request Forgery (CSRF) Vulnerability

CVSS 3.1
9.8 critical
EPSS
15%p96
Published
()
KEV added
AI analysis

CVE-2020-10181 is a cross-site request forgery (CSRF, CWE-352) flaw in the goform/formEMR30 web endpoint of Sumavision Enhanced Multimedia Router (EMR) firmware. A crafted request to that endpoint — demonstrated with a setString=new_user administrator 123456 parameter — causes the device to create a new account with full administrator privileges, and the CVSS vector (no privileges required, no user interaction) together with the public proof-of-concept scripts indicates the endpoint accepts such requests without authentication. An attacker who can reach the device's web interface gains complete administrative control of the router, enabling configuration changes and a potential foothold inside cable/broadcast headend networks. Affected users are operators running the Sumavision EMR, with firmware version 3.0.4.27 explicitly named in the advisory. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), confirming exploitation in the wild, and its 14.7% EPSS score (96th percentile) indicates a moderate probability of ongoing exploitation.

What to do: Upgrade EMR firmware per vendor instructions as required by the CISA KEV listing (no fixed version number is available in the data). Until patched, restrict internet exposure of the EMR web management interface, block untrusted access to the goform/formEMR30 endpoint, and audit the device's user accounts for unexpectedly created administrators (e.g., an 'administrator' account with a default password).

Affected
Sumavision Enhanced Multimedia Router (EMR) firmware3.0.4.27 (explicitly named affected version; other versions not specified in available data)
Estimated exposure
nichelikely low thousands of units deployed worldwide, with an internet-exposed subset plausibly in the hundreds — The EMR is a specialized cable/broadcast headend appliance rather than mass-market software, and the limited public PoC/scan coverage suggests a small exposed population; exact install counts are unknown.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

goform/formEMR30 in Sumavision Enhanced Multimedia Router (EMR) 3.0.4.27 allows creation of arbitrary users with elevated privileges (administrator) on a device, as demonstrated by a setString=new_user administrator 123456 request.

CISA Known Exploited Vulnerability
Affected
Sumavision Enhanced Multimedia Router (EMR)
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
sumavision
Products
enhanced multimedia router firmware
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.