// For flags

CVE-2020-7357

Cayin CMS Command Injection

Severity Score

9.9
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Cayin CMS suffers from an authenticated OS semi-blind command injection vulnerability using default credentials. This can be exploited to inject and execute arbitrary shell commands as the root user through the 'NTP_Server_IP' HTTP POST parameter in system.cgi page. This issue affects several branches and versions of the CMS application, including CME-SE, CMS-60, CMS-40, CMS-20, and CMS version 8.2, 8.0, and 7.5.

Cayin CMS sufre de una vulnerabilidad de inyección de comando semi-ciega autenticada del Sistema Operativo usando credenciales predeterminadas. Esta puede ser explotada para inyectar y ejecutar comandos de shell arbitrarios como usuario root por medio del parámetro POST HTTP "NTP_Server_IP" en la página system.cgi. Este problema afecta a varias ramas y versiones de la aplicación CMS, incluyendo a CME-SE, CMS-60, CMS-40, CMS-20 y CMS versión 8.2, 8.0 y 7.5

*Credits: This issue was discovered by Gjoko Krstic of Zero Science Lab.
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-01-21 CVE Reserved
  • 2020-06-18 CVE Published
  • 2024-09-17 CVE Updated
  • 2024-09-17 EPSS Updated
  • 2024-09-17 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cayintech
Search vendor "Cayintech"
Cms-se Firmware
Search vendor "Cayintech" for product "Cms-se Firmware"
11.0
Search vendor "Cayintech" for product "Cms-se Firmware" and version "11.0"
19179
Affected
in Cayintech
Search vendor "Cayintech"
Cms-se
Search vendor "Cayintech" for product "Cms-se"
--
Safe
Cayintech
Search vendor "Cayintech"
Cms-se Firmware
Search vendor "Cayintech" for product "Cms-se Firmware"
11.0
Search vendor "Cayintech" for product "Cms-se Firmware" and version "11.0"
19025
Affected
in Cayintech
Search vendor "Cayintech"
Cms-se
Search vendor "Cayintech" for product "Cms-se"
--
Safe
Cayintech
Search vendor "Cayintech"
Cms-se Firmware
Search vendor "Cayintech" for product "Cms-se Firmware"
11.0
Search vendor "Cayintech" for product "Cms-se Firmware" and version "11.0"
18325
Affected
in Cayintech
Search vendor "Cayintech"
Cms-se
Search vendor "Cayintech" for product "Cms-se"
--
Safe
Cayintech
Search vendor "Cayintech"
Cms-se-lxc Firmware
Search vendor "Cayintech" for product "Cms-se-lxc Firmware"
--
Affected
in Cayintech
Search vendor "Cayintech"
Cms-se-lxc
Search vendor "Cayintech" for product "Cms-se-lxc"
--
Safe
Cayintech
Search vendor "Cayintech"
Cms-60 Firmware
Search vendor "Cayintech" for product "Cms-60 Firmware"
11.0
Search vendor "Cayintech" for product "Cms-60 Firmware" and version "11.0"
19025
Affected
in Cayintech
Search vendor "Cayintech"
Cms-60
Search vendor "Cayintech" for product "Cms-60"
--
Safe
Cayintech
Search vendor "Cayintech"
Cms-40 Firmware
Search vendor "Cayintech" for product "Cms-40 Firmware"
9.0
Search vendor "Cayintech" for product "Cms-40 Firmware" and version "9.0"
14197
Affected
in Cayintech
Search vendor "Cayintech"
Cms-40
Search vendor "Cayintech" for product "Cms-40"
--
Safe
Cayintech
Search vendor "Cayintech"
Cms-40 Firmware
Search vendor "Cayintech" for product "Cms-40 Firmware"
9.0
Search vendor "Cayintech" for product "Cms-40 Firmware" and version "9.0"
14199
Affected
in Cayintech
Search vendor "Cayintech"
Cms-40
Search vendor "Cayintech" for product "Cms-40"
--
Safe
Cayintech
Search vendor "Cayintech"
Cms-40 Firmware
Search vendor "Cayintech" for product "Cms-40 Firmware"
9.0
Search vendor "Cayintech" for product "Cms-40 Firmware" and version "9.0"
14093
Affected
in Cayintech
Search vendor "Cayintech"
Cms-40
Search vendor "Cayintech" for product "Cms-40"
--
Safe
Cayintech
Search vendor "Cayintech"
Cms-20 Firmware
Search vendor "Cayintech" for product "Cms-20 Firmware"
9.0
Search vendor "Cayintech" for product "Cms-20 Firmware" and version "9.0"
14197
Affected
in Cayintech
Search vendor "Cayintech"
Cms-20
Search vendor "Cayintech" for product "Cms-20"
--
Safe
Cayintech
Search vendor "Cayintech"
Cms-20 Firmware
Search vendor "Cayintech" for product "Cms-20 Firmware"
9.0
Search vendor "Cayintech" for product "Cms-20 Firmware" and version "9.0"
14092
Affected
in Cayintech
Search vendor "Cayintech"
Cms-20
Search vendor "Cayintech" for product "Cms-20"
--
Safe
Cayintech
Search vendor "Cayintech"
Cms
Search vendor "Cayintech" for product "Cms"
7.5
Search vendor "Cayintech" for product "Cms" and version "7.5"
11175
Affected
Cayintech
Search vendor "Cayintech"
Cms
Search vendor "Cayintech" for product "Cms"
8.0
Search vendor "Cayintech" for product "Cms" and version "8.0"
11175
Affected
Cayintech
Search vendor "Cayintech"
Cms
Search vendor "Cayintech" for product "Cms"
8.2
Search vendor "Cayintech" for product "Cms" and version "8.2"
12199
Affected