CVE-2020-36910Public exploitNetwork attack vector

Authenticated root command execution via NTP parameter

Published Jan 6, 2026 · Updated Jan 6, 2026

OS command injection in CAYIN SMP media players allows remote authenticated users to execute arbitrary shell commands as root. The system.cgi and wizard_system.cgi handlers pass the NTP_Server_IP value to a shell command without neutralizing command separators. Access requires web authentication, but the published exploit uses the default webadmin/admin credentials and returns command output over HTTP.

CVSS severity8.7
High
EPSS probability1.45%
Next 30 days · Sep 16, 2026
Known exploitationUnconfirmed
Based on sourced intelligence
Hinoki checkNot available
Coverage for this vulnerability

See if you're affected

Explore vulnerability checks for your environment with Hinoki.

Book a demo

Summary

What happened

OS command injection in CAYIN SMP media players allows remote authenticated users to execute arbitrary shell commands as root. The system.cgi and wizard_system.cgi handlers pass the NTP_Server_IP value to a shell command without neutralizing command separators. Access requires web authentication, but the published exploit uses the default webadmin/admin credentials and returns command output over HTTP.

The record

CVE
CVE-2020-36910
Published
Jan 6, 2026
Updated
Jan 6, 2026
Vendor
CAYIN Technology Co., Ltd.
Product
SMP-NEO2
Classifications
CWE-78, T1059.004
Attack vector
network
Privileges
authenticated

Timeline

How it unfolded

  1. Jan 6, 2026CVE publishedPublication date reported by the CVE source.
  2. Jan 6, 2026Record updatedLatest update available in the CVE record.

Exploitability

Present is not the same as exploitable

Compare your product and version with the public record. A matching version still requires validation against your environment.

Is a vulnerable build present?

Compare these published version ranges with your installed build and any vendor patches.

  1. Affected versionversion=1.0

What conditions does exploitation require?

Attack vectornetwork
Required privilegesauthenticated

What is affected?

CAYIN Technology Co., Ltd. · SMP-NEO2version=1.0
CAYIN Technology Co., Ltd. · SMP-2310version=3.0
CAYIN Technology Co., Ltd. · SMP-200version=1.0 Build 12331; version=1.0 Build 13080
CAYIN Technology Co., Ltd. · SMP-300version=1.0 Build 14177
CAYIN Technology Co., Ltd. · SMP-1000version=1.0 Build 14099
CAYIN Technology Co., Ltd. · SMP-PROPLUSversion=1.5 Build 10081
CAYIN Technology Co., Ltd. · SMP-NEOversion=1.0
CAYIN Technology Co., Ltd. · SMP-4000version=1.0 Build 14087; version=1.0 Build 14092; version=1.0 Build 14098
CAYIN Technology Co., Ltd. · SMP-2210version=3.0 Build 19025
CAYIN Technology Co., Ltd. · SMP-2100version=10.0 Build 16228; version=3.0
CAYIN Technology Co., Ltd. · SMP-2000version=1.0 Build 14087; version=1.0 Build 14167
CAYIN Technology Co., Ltd. · SMP-8000QDversion=3.0
CAYIN Technology Co., Ltd. · SMP-2300version=3.0 Build 19316
CAYIN Technology Co., Ltd. · SMP-WEBPLUSversion=6.5 Build 11126
CAYIN Technology Co., Ltd. · SMP-WEB4version=1.0 Build 10301; version=1.5 Build 11126; version=1.5 Build 11476; version=2.0 Build 11175; version=2.0 Build 13073
CAYIN Technology Co., Ltd. · SMP-6000version=1.0 Build 14062; version=1.0 Build 14069; version=1.0 Build 14090; version=1.0 Build 14097; version=1.0 Build 14167; version=1.0 Build 14199; version=1.0 Build 14246; version=3.0 Build 19025
CAYIN Technology Co., Ltd. · SMP-8000version=3.0
CAYIN Technology Co., Ltd. · SMP-2200version=3.0 Build 19025; version=3.0 Build 19029
CAYIN Technology Co., Ltd. · SMP-PRO4version=1.0

Published CVSS scores

8.8VulnCheckCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
8.7VulnCheckCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CVSS describes severity. EPSS estimates exploitation probability.

Attacks

What attackers are doing with it

Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.

Daily unique IPsNo honeypot observations are available for this CVE in the selected window.

No observations available

Sep 9, 2026Sep 15, 2026
Latest reporting daySep 15, 2026
Latest daily unique IPsUnavailable
Prior 30-day averageUnavailable
SourceShadowserver honeypots (KEV)
Vectornetwork
Privilegesauthenticated
Known exploitationUnconfirmed
Public exploitPublished

Weakness, pattern, technique

CWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
T1059.004Unix Shell

Public exploit references

Labels summarize the accepted research assessment. They do not indicate a test against your environment.

Technologies

Your stack

See the directory against your own environment.

Your stack

Check the software in your environment

Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.

Book a demo