CVE Feed

    Dashboard / CVE / CVE-2020-7357

    CVE-2020-7357

    Cayin CMS suffers from an authenticated OS semi-blind command injection vulnerability using default credentials. This can be exploited to inject and execute arbitrary shell commands as the root user through the 'NTP_Server_IP' HTTP POST parameter in system.cgi page. This issue affects several branches and versions of the CMS application, including CME-SE, CMS-60, CMS-40, CMS-20, and CMS version 8.2, 8.0, and 7.5.

    Published:Aug 6, 2020
    Last Modified:Nov 21, 2024
    EPS:Aug 6, 2020
    EPSS Score:0.75039
    CVSS Score:9.6

    Affected Products

    Vendor
    Cayintech
    Product
    Cms
    Vendor
    Cayintech
    Product
    Cms-20
    Vendor
    Cayintech
    Product
    Cms-20 Firmware
    Vendor
    Cayintech
    Product
    Cms-40
    Vendor
    Cayintech
    Product
    Cms-40 Firmware
    Vendor
    Cayintech
    Product
    Cms-60
    Vendor
    Cayintech
    Product
    Cms-60 Firmware
    Vendor
    Cayintech
    Product
    Cms-se
    Vendor
    Cayintech
    Product
    Cms-se-lxc
    Vendor
    Cayintech
    Product
    Cms-se-lxc Firmware
    Vendor
    Cayintech
    Product
    Cms-se Firmware

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High