CVE-2020-7357
PoC ×2—CVSS 3.1
9.9 critical
EPSS
32%p98
Published
()
Modified
Description
Cayin CMS suffers from an authenticated OS semi-blind command injection vulnerability using default credentials. This can be exploited to inject and execute arbitrary shell commands as the root user through the 'NTP_Server_IP' HTTP POST parameter in system.cgi page. This issue affects several branches and versions of the CMS application, including CME-SE, CMS-60, CMS-40, CMS-20, and CMS version 8.2, 8.0, and 7.5.
- Vendors
- cayintech
- Products
- cms-se firmware, cms-se-lxc firmware, cms-60 firmware, cms-40 firmware, cms-20 firmware, cms
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.