vendor:
Cayin Signage Media Player
by:
LiquidWorm
7.8
CVSS
HIGH
Remote Command Injection
78
CWE
Product Name: Cayin Signage Media Player
Affected Version From: SMP-8000QD v3.0
Affected Version To: SMP-300 v1.0 Build 14177
Patch Exists: YES
Related CWE: N/A
CPE: a:cayin_technology:cayin_signage_media_player
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows, Linux, Mac
2020
Cayin Signage Media Player 3.0 – Remote Command Injection (root)
CAYIN Technology provides Digital Signage solutions, including media players, servers, and software. The SMP-8000QD, SMP-8000, SMP-6000, SMP-4000, SMP-2310, SMP-2300, SMP-2210, SMP-2200, SMP-2100, SMP-2000, SMP-1000, SMP-PROPLUS, SMP-WEBPLUS, SMP-WEB4, SMP-PRO4, SMP-NEO2, SMP-NEO, and SMP-300 media players are vulnerable to remote command injection as root.
Mitigation:
The vendor has released a patch to address this vulnerability.