CVE-2020-36910 - CVE House
Back to Database
Status published High CVE-2020-36910

Cayin Signage Media Player 3.0 Authenticated Remote Command Injection via NTP Parameter

Vulnerability Description

Cayin Signage Media Player 3.0 contains an authenticated remote command injection vulnerability in system.cgi and wizard_system.cgi pages. Attackers can exploit the 'NTP_Server_IP' parameter with default credentials to execute arbitrary shell commands as root.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-36910

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • LiquidWorm as Gjoko Krstic of Zero Science Lab

Affected Vendor

CAYIN Technology

View all reports →

Affected Software

SMP-8000QD, SMP-8000, SMP-6000, SMP-4000, SMP-2310, SMP-2300, SMP-2210, SMP-2200, SMP-2100, SMP-2000, SMP-1000, SMP-PROPLUS, SMP-WEBPLUS, SMP-WEB4, SMP-300, SMP-200, SMP-PRO4, SMP-NEO2, SMP-NEO
Vulnerable Versions:
3.0, 3.0 Build 19025, 1.0 Build 14246, 1.0 Build 14199, 1.0 Build 14167, 1.0 Build 14097, 1.0 Build 14090, 1.0 Build 14069, 1.0 Build 14062, 1.0 Build 14098, 1.0 Build 14092, 1.0 Build 14087, 3.0 Build 19316, 3.0 Build 19029, 10.0 Build 16228, 1.0 Build 14099, 1.5 Build 10081, 6.5 Build 11126, 2.0 Build 13073, 2.0 Build 11175, 1.5 Build 11476, 1.5 Build 11126, 1.0 Build 10301, 1.0 Build 14177, 1.0 Build 13080, 1.0 Build 12331, 1.0

Timeline

Official Publish: January 6th, 2026
Last Modified: July 15th, 2026
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)