Vulnerability record · CVE-2020-7357 · published 6 August 2020
CVE-2020-7357: Cayintech cms-se firmware os command injection vulnerability
Cayintech · Cms Se Firmware
Cayin CMS suffers from an authenticated OS semi-blind command injection vulnerability using default credentials. This can be exploited to inject and execute arbitrary shell commands as the root user through the 'NTP_Server_IP' HTTP POST parameter in system.cgi page. This issue affects several branches and versions of the CMS application, including CME-SE, CMS-60, CMS-40, CMS-20, and CMS version 8.2, 8.0, and 7.5.
Description
Cayin CMS suffers from an authenticated OS semi-blind command injection vulnerability using default credentials. This can be exploited to inject and execute arbitrary shell commands as the root user through the 'NTP_Server_IP' HTTP POST parameter in system.cgi page. This issue affects several branches and versions of the CMS application, including CME-SE, CMS-60, CMS-40, CMS-20, and CMS version 8.2, 8.0, and 7.5.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://exchange.xforce.ibmcloud.com/vulnerabilities/182925 | Third Party AdvisoryVDB Entry |
| https://github.com/rapid7/metasploit-framework/pull/13607 | ExploitPatch |
| https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5570.php | ExploitThird Party Advisory |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/182925 | Third Party AdvisoryVDB Entry |
| https://github.com/rapid7/metasploit-framework/pull/13607 | ExploitPatch |
| https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5570.php | ExploitThird Party Advisory |
Track CVE-2020-7357 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-7357), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.