CVE-2020-7357
Cayin CMS Command Injection
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
Cayin CMS suffers from an authenticated OS semi-blind command injection vulnerability using default credentials. This can be exploited to inject and execute arbitrary shell commands as the root user through the 'NTP_Server_IP' HTTP POST parameter in system.cgi page. This issue affects several branches and versions of the CMS application, including CME-SE, CMS-60, CMS-40, CMS-20, and CMS version 8.2, 8.0, and 7.5.
Cayin CMS sufre de una vulnerabilidad de inyección de comando semi-ciega autenticada del Sistema Operativo usando credenciales predeterminadas. Esta puede ser explotada para inyectar y ejecutar comandos de shell arbitrarios como usuario root por medio del parámetro POST HTTP "NTP_Server_IP" en la página system.cgi. Este problema afecta a varias ramas y versiones de la aplicación CMS, incluyendo a CME-SE, CMS-60, CMS-40, CMS-20 y CMS versión 8.2, 8.0 y 7.5
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-01-21 CVE Reserved
- 2020-06-18 CVE Published
- 2024-09-17 CVE Updated
- 2024-09-17 EPSS Updated
- 2024-09-17 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/rapid7/metasploit-framework/pull/13607 | 2024-09-17 | |
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5570.php | 2024-09-17 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/182925 | 2023-07-27 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cayintech Search vendor "Cayintech" | Cms-se Firmware Search vendor "Cayintech" for product "Cms-se Firmware" | 11.0 Search vendor "Cayintech" for product "Cms-se Firmware" and version "11.0" | 19179 |
Affected
| in | Cayintech Search vendor "Cayintech" | Cms-se Search vendor "Cayintech" for product "Cms-se" | - | - |
Safe
|
Cayintech Search vendor "Cayintech" | Cms-se Firmware Search vendor "Cayintech" for product "Cms-se Firmware" | 11.0 Search vendor "Cayintech" for product "Cms-se Firmware" and version "11.0" | 19025 |
Affected
| in | Cayintech Search vendor "Cayintech" | Cms-se Search vendor "Cayintech" for product "Cms-se" | - | - |
Safe
|
Cayintech Search vendor "Cayintech" | Cms-se Firmware Search vendor "Cayintech" for product "Cms-se Firmware" | 11.0 Search vendor "Cayintech" for product "Cms-se Firmware" and version "11.0" | 18325 |
Affected
| in | Cayintech Search vendor "Cayintech" | Cms-se Search vendor "Cayintech" for product "Cms-se" | - | - |
Safe
|
Cayintech Search vendor "Cayintech" | Cms-se-lxc Firmware Search vendor "Cayintech" for product "Cms-se-lxc Firmware" | - | - |
Affected
| in | Cayintech Search vendor "Cayintech" | Cms-se-lxc Search vendor "Cayintech" for product "Cms-se-lxc" | - | - |
Safe
|
Cayintech Search vendor "Cayintech" | Cms-60 Firmware Search vendor "Cayintech" for product "Cms-60 Firmware" | 11.0 Search vendor "Cayintech" for product "Cms-60 Firmware" and version "11.0" | 19025 |
Affected
| in | Cayintech Search vendor "Cayintech" | Cms-60 Search vendor "Cayintech" for product "Cms-60" | - | - |
Safe
|
Cayintech Search vendor "Cayintech" | Cms-40 Firmware Search vendor "Cayintech" for product "Cms-40 Firmware" | 9.0 Search vendor "Cayintech" for product "Cms-40 Firmware" and version "9.0" | 14197 |
Affected
| in | Cayintech Search vendor "Cayintech" | Cms-40 Search vendor "Cayintech" for product "Cms-40" | - | - |
Safe
|
Cayintech Search vendor "Cayintech" | Cms-40 Firmware Search vendor "Cayintech" for product "Cms-40 Firmware" | 9.0 Search vendor "Cayintech" for product "Cms-40 Firmware" and version "9.0" | 14199 |
Affected
| in | Cayintech Search vendor "Cayintech" | Cms-40 Search vendor "Cayintech" for product "Cms-40" | - | - |
Safe
|
Cayintech Search vendor "Cayintech" | Cms-40 Firmware Search vendor "Cayintech" for product "Cms-40 Firmware" | 9.0 Search vendor "Cayintech" for product "Cms-40 Firmware" and version "9.0" | 14093 |
Affected
| in | Cayintech Search vendor "Cayintech" | Cms-40 Search vendor "Cayintech" for product "Cms-40" | - | - |
Safe
|
Cayintech Search vendor "Cayintech" | Cms-20 Firmware Search vendor "Cayintech" for product "Cms-20 Firmware" | 9.0 Search vendor "Cayintech" for product "Cms-20 Firmware" and version "9.0" | 14197 |
Affected
| in | Cayintech Search vendor "Cayintech" | Cms-20 Search vendor "Cayintech" for product "Cms-20" | - | - |
Safe
|
Cayintech Search vendor "Cayintech" | Cms-20 Firmware Search vendor "Cayintech" for product "Cms-20 Firmware" | 9.0 Search vendor "Cayintech" for product "Cms-20 Firmware" and version "9.0" | 14092 |
Affected
| in | Cayintech Search vendor "Cayintech" | Cms-20 Search vendor "Cayintech" for product "Cms-20" | - | - |
Safe
|
Cayintech Search vendor "Cayintech" | Cms Search vendor "Cayintech" for product "Cms" | 7.5 Search vendor "Cayintech" for product "Cms" and version "7.5" | 11175 |
Affected
| ||||||
Cayintech Search vendor "Cayintech" | Cms Search vendor "Cayintech" for product "Cms" | 8.0 Search vendor "Cayintech" for product "Cms" and version "8.0" | 11175 |
Affected
| ||||||
Cayintech Search vendor "Cayintech" | Cms Search vendor "Cayintech" for product "Cms" | 8.2 Search vendor "Cayintech" for product "Cms" and version "8.2" | 12199 |
Affected
|