Home

Description

Cayin Signage Media Player 3.0 contains an authenticated remote command injection vulnerability in system.cgi and wizard_system.cgi pages. Attackers can exploit the 'NTP_Server_IP' parameter with default credentials to execute arbitrary shell commands as root.

PUBLISHED Reserved 2026-01-03 | Published 2026-01-06 | Updated 2026-01-06 | Assigner VulnCheck




HIGH: 8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
HIGH: 8.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Problem types

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Product status

3.0
affected

3.0
affected

3.0 Build 19025
affected

1.0 Build 14246
affected

1.0 Build 14199
affected

1.0 Build 14167
affected

1.0 Build 14097
affected

1.0 Build 14090
affected

1.0 Build 14069
affected

1.0 Build 14062
affected

1.0 Build 14098
affected

1.0 Build 14092
affected

1.0 Build 14087
affected

3.0
affected

3.0 Build 19316
affected

3.0 Build 19025
affected

3.0 Build 19029
affected

3.0 Build 19025
affected

10.0 Build 16228
affected

3.0
affected

1.0 Build 14167
affected

1.0 Build 14087
affected

1.0 Build 14099
affected

1.5 Build 10081
affected

6.5 Build 11126
affected

2.0 Build 13073
affected

2.0 Build 11175
affected

1.5 Build 11476
affected

1.5 Build 11126
affected

1.0 Build 10301
affected

1.0 Build 14177
affected

1.0 Build 13080
affected

1.0 Build 12331
affected

1.0
affected

1.0
affected

1.0
affected

Credits

LiquidWorm as Gjoko Krstic of Zero Science Lab finder

References

www.exploit-db.com/exploits/48557 (ExploitDB-48557) exploit

www.cayintech.com (Cayin Technology Official Website) product

www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5569.php (Zero Science Lab Disclosure (ZSL-2020-5569)) third-party-advisory

packetstorm.news/files/id/157942 (Packet Storm Security Exploit Entry) exploit

exchange.xforce.ibmcloud.com/vulnerabilities/182924 (IBM X-Force Vulnerability Exchange) vdb-entry

cxsecurity.com/issue/WLB-2020060049 (CXSecurity Vulnerability Listing) exploit

www.vulncheck.com/...ote-command-injection-via-ntp-parameter (VulnCheck Advisory: Cayin Signage Media Player 3.0 Authenticated Remote Command Injection via NTP Parameter) third-party-advisory

cve.org (CVE-2020-36910)

nvd.nist.gov (CVE-2020-36910)

Download JSON