CVE-2020-36910 | CAYIN SMP-8000QD 3.0 system.cgi NTP_Server_IP os command injection (Exploit 48557 / EUVD-2026-1026)
A vulnerability, which was classified as critical, was found in CAYIN SMP-8000QD, SMP-8000, SMP-6000, SMP-4000, SMP-2310, SMP-2300, SMP-2210, SMP-2200, SMP-2100, SMP-2000, SMP-1000, SMP-PROPLUS, SMP-WEBPLUS, SMP-WEB4, SMP-300, SMP-200, SMP-PRO4, SMP-NEO2 and SMP-NEO 3.0. The impacted element is an unknown function of the file system.cgi. Such manipulation of the argument NTP_Server_IP leads to os command injection.
This vulnerability is listed as CVE-2020-36910. The attack may be performed from remote. There is no available exploit.