Authenticated Remote Command Injection in Cayin Signage Media Player by Cayin Technology
CVE-2020-36910
Key Information:
- Vendor
Cayin Technology
- Vendor
- CVE Published:
- 6 January 2026
Badges
What is CVE-2020-36910?
Cayin Signage Media Player 3.0 is susceptible to an authenticated remote command injection vulnerability impacting the system.cgi and wizard_system.cgi pages. This flaw allows attackers to exploit the 'NTP_Server_IP' parameter while using default credentials, enabling them to execute arbitrary shell commands with root privileges. Effective measures should be implemented to secure the application against unauthorized access and code execution exploits.
Affected Version(s)
SMP-1000 1.0 Build 14099
SMP-200 1.0 Build 13080
SMP-200 1.0 Build 12331
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
