9.8
CVSSv3

CVE-2020-10181

Published: 11/03/2020 Updated: 12/07/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

goform/formEMR30 in Sumavision Enhanced Multimedia Router (EMR) 3.0.4.27 allows creation of arbitrary users with elevated privileges (administrator) on a device, as demonstrated by a setString=new_user<*1*>administrator<*1*>123456 request.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sumavision enhanced_multimedia_router_firmware 3.0.4.27

Exploits

Enhanced Multimedia Router version 30427 suffers from a cross site request forgery vulnerability ...

Github Repositories

Sumavision EMR30 - (CVE-2020-10181) Video wwwyoutubecom/watch?v=Ufcj4D9eA5o