PT-2026-1445 · Cayin · Cayin Signage Media Player
CVE-2020-36910
·
Publicado
2026-01-06
·
Atualizado
2026-01-06
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cayin Signage Media Player version 3.0
Description
The software contains an authenticated remote command injection issue in the
system.cgi and wizard system.cgi pages. An attacker can exploit the NTP Server IP parameter using default credentials to execute arbitrary shell commands as root.Recommendations
Apply any available updates to address the issue in the
system.cgi and wizard system.cgi pages.
Change the default credentials to prevent unauthorized access.
Restrict access to the system.cgi and wizard system.cgi pages.
As a temporary workaround, avoid using the NTP Server IP parameter.Exploit
Correção
OS Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cayin Signage Media Player