Exploitation Summary
EIP tracks 1 public exploit for CVE-2020-36910. PoCs published by LiquidWorm.
AI-analyzed exploit summary This Python script exploits an authenticated remote command injection vulnerability in Cayin Signage Media Player 3.0 by injecting arbitrary shell commands via the 'NTP_Server_IP' parameter in system.cgi. The exploit uses default credentials ('webadmin/admin') to authenticate and execute commands as root.
Description
Cayin Signage Media Player 3.0 contains an authenticated remote command injection vulnerability in system.cgi and wizard_system.cgi pages. Attackers can exploit the 'NTP_Server_IP' parameter with default credentials to execute arbitrary shell commands as root.
Exploits (1)
This Python script exploits an authenticated remote command injection vulnerability in Cayin Signage Media Player 3.0 by injecting arbitrary shell commands via the 'NTP_Server_IP' parameter in system.cgi. The exploit uses default credentials ('webadmin/admin') to authenticate and execute commands as root.
References (7)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H