Cayin Signage Media Player 3.0 contains an authenticated remote command injection vulnerability in system.cgi and wizard_system.cgi pages. Attackers can exploit the 'NTP_Server_IP' parameter with default credentials to execute arbitrary shell commands as root.
Metrics
Affected Vendors & Products
References
History
Tue, 06 Jan 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Jan 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cayin Signage Media Player 3.0 contains an authenticated remote command injection vulnerability in system.cgi and wizard_system.cgi pages. Attackers can exploit the 'NTP_Server_IP' parameter with default credentials to execute arbitrary shell commands as root. | |
| Title | Cayin Signage Media Player 3.0 Authenticated Remote Command Injection via NTP Parameter | |
| Weaknesses | CWE-78 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-01-06T19:32:13.853Z
Reserved: 2026-01-03T14:10:13.300Z
Link: CVE-2020-36910
Updated: 2026-01-06T19:32:01.236Z
Status : Received
Published: 2026-01-06T16:15:46.847
Modified: 2026-01-06T16:15:46.847
Link: CVE-2020-36910
No data.
OpenCVE Enrichment
No data.