ZeroHour

Vulnerabilities

1 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-10181
CSRF in Sumavision EMR Lets Attackers Create Rogue Administrator Accounts

CVE-2020-10181 is a cross-site request forgery (CSRF, CWE-352) flaw in the goform/formEMR30 web endpoint of Sumavision Enhanced Multimedia Router (EMR) firmware. A crafted request to that endpoint — demonstrated with a setString=new_user administrator 123456 parameter — causes the device to create a new account with full administrator privileges, and the CVSS vector (no privileges required, no user interaction) together with the public proof-of-concept scripts indicates the endpoint accepts such requests without authentication. An attacker who can reach the device's web interface gains complete administrative control of the router, enabling configuration changes and a potential foothold inside cable/broadcast headend networks. Affected users are operators running the Sumavision EMR, with firmware version 3.0.4.27 explicitly named in the advisory. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), confirming exploitation in the wild, and its 14.7% EPSS score (96th percentile) indicates a moderate probability of ongoing exploitation.

Do: Upgrade EMR firmware per vendor instructions as required by the CISA KEV listing (no fixed version number is available in the data). Until patched, restrict internet exposure of the EMR web management interface, block untrusted access to the goform/formEMR30 endpoint, and audit the device's user accounts for unexpectedly created administrators (e.g., an 'administrator' account with a default password).

9.815% KEV PoC ×3
  • Sumavision Enhanced Multimedia Router (EMR) firmware 3.0.4.27 (explicitly named affected version; other versions not specified in available data)
nichelikely low thousands of units deployed worldwide, with an internet-exposed subset plausibly in the hundreds