vendor:
Enhanced Multimedia Router
by:
Miguel Mendez Z.
9.8
CVSS
CRITICAL
Cross-Site Request Forgery
352
CWE
Product Name: Enhanced Multimedia Router
Affected Version From: 3.0.4.27
Affected Version To: 3.0.4.27
Patch Exists: YES
Related CWE: CVE-2020-10181
CPE: a:sumavision:enhanced_multimedia_router:3.0.4.27
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2020
Enhanced Multimedia Router 3.0.4.27 – Cross-Site Request Forgery (Add Admin)
A Cross-Site Request Forgery (CSRF) vulnerability exists in Enhanced Multimedia Router 3.0.4.27 which allows an attacker to add an administrator user with a specified username and password. This is achieved by sending a POST request with the type, cmd, language, slotNo and setString parameters to the formEMR30 page. The setString parameter contains the username, administrator role and password of the user to be added. An attacker can exploit this vulnerability by tricking an authenticated user into clicking a malicious link.
Mitigation:
The vendor has released a patch to address this vulnerability. Users should update to the latest version of Enhanced Multimedia Router.