CVE-2020-36910 Details
Description
Cayin Signage Media Player 3.0 contains an authenticated remote command injection vulnerability in system.cgi and wizard_system.cgi pages. Attackers can exploit the 'NTP_Server_IP' parameter with default credentials to execute arbitrary shell commands as root.
An authenticated remote command injection vulnerability has been identified in Cayin Signage Media Player version 3.0. This vulnerability exists in the 'system.cgi' and 'wizard_system.cgi' pages, where the 'NTP_Server_IP' parameter can be exploited to execute arbitrary shell commands as the root user. The vulnerability arises from improper input validation, and can be exploited using default credentials.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 6, 2026CISA-ADP
Assessed Jan 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Cayin Signage Media Player | All versions |
CPE
Remediation
| |
| Cayin SMP-8000QD | All versions |
CPE
Remediation
| |
| Cayin SMP-8000 | All versions |
CPE
Remediation
| |
| Cayin SMP-6000 | All versions |
CPE
Remediation
| |
| Cayin SMP-4000 | All versions |
CPE
Remediation
| |
| Cayin SMP-2310 | All versions |
CPE
Remediation
| |
| Cayin SMP-2300 | All versions |
CPE
Remediation
| |
| Cayin SMP-2210 | All versions |
CPE
Remediation
| |
| Cayin SMP-2200 | All versions |
CPE
Remediation
| |
| Cayin SMP-2100 | All versions |
CPE
Remediation
| |
| Cayin SMP-2000 | All versions |
CPE
Remediation
| |
| Cayin SMP-1000 | All versions |
CPE
Remediation
| |
| Cayin SMP-PROPLUS | All versions |
CPE
Remediation
| |
| Cayin SMP-WEBPLUS | All versions |
CPE
Remediation
| |
| Cayin SMP-WEB4 | All versions |
CPE
Remediation
| |
| Cayin SMP-300 | All versions |
CPE
Remediation
| |
| Cayin SMP-200 | All versions |
CPE
Remediation
| |
| Cayin SMP-PRO4 | SMP-8000QD v3.0 SMP-8000 v3.0 SMP-6000 v3.0 Build 19025 SMP-6000 v1.0 Build 14246 SMP-6000 v1.0 Build 14199 SMP-6000 v1.0 Build 14167 SMP-6000 v1.0 Build 14097 SMP-6000 v1.0 Build 14090 SMP-6000 v1.0 Build 14069 SMP-6000 v1.0 Build 14062 SMP-4000 v1.0 Build 14098 SMP-4000 v1.0 Build 14092 SMP-4000 v1.0 Build 14087 SMP-2310 v3.0 SMP-2300 v3.0 Build 19316 SMP-2210 v3.0 Build 19025 SMP-2200 v3.0 Build 19029 SMP-2200 v3.0 Build 19025 SMP-2100 v10.0 Build 16228 SMP-2100 v3.0 SMP-2000 v1.0 Build 14167 SMP-2000 v1.0 Build 14087 SMP-1000 v1.0 Build 14099 SMP-PROPLUS v1.5 Build 10081 SMP-WEBPLUS v6.5 Build 11126 SMP-WEB4 v2.0 Build 13073 SMP-WEB4 v2.0 Build 11175 SMP-WEB4 v1.5 Build 11476 SMP-WEB4 v1.5 Build 11126 SMP-WEB4 v1.0 Build 10301 SMP-300 v1.0 Build 14177 SMP-200 v1.0 Build 13080 SMP-200 v1.0 Build 12331 SMP-PRO4 v1.0 SMP-NEO2 v1.0 SMP-NEO v1.0 |
CPE
Remediation
| |
| Cayin SMP-NEO2 | All versions |
CPE
Remediation
| |
| Cayin SMP-NEO | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 6, 2026 | New CVE Received | [email protected] |
Volerion