High severity8.8NVD Advisory· Published Jan 6, 2026· Updated Apr 15, 2026
CVE-2020-36910
CVE-2020-36910
Description
Cayin Signage Media Player 3.0 contains an authenticated remote command injection vulnerability in system.cgi and wizard_system.cgi pages. Attackers can exploit the 'NTP_Server_IP' parameter with default credentials to execute arbitrary shell commands as root.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- cxsecurity.com/issue/WLB-2020060049nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/182924nvd
- packetstorm.news/files/id/157942nvd
- www.cayintech.comnvd
- www.exploit-db.com/exploits/48557nvd
- www.vulncheck.com/advisories/cayin-signage-media-player-authenticated-remote-command-injection-via-ntp-parameternvd
- www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5569.phpnvd
News mentions
0No linked articles in our index yet.