CVE-2020-10181
Published · Updated
83Vexday Risk Score
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
ssvc Actcvss 9.8epss 15%
from disclosure to weapon
Published on NVDMar 11
CISA KEV+602d
exploitation probability
15%top 3% of all CVEs
observed exploitation
yesCISA + VulnCheck
1 public exploit(s)
Action required by CISAfederal deadline: 2022-05-03
Apply updates per vendor instructions.
In short
A vulnerability in Sumavision Enhanced Multimedia Router allows attackers to create new administrator accounts without authentication, giving them complete control of the device.
Technical detail
CWE-352 (CSRF/missing authorization) in goform/formEMR30 endpoint permits unauthenticated user creation with administrator privileges via crafted setString parameter. No authentication or CSRF tokens are validated, allowing remote attackers to establish persistent administrative access to the router.
Summary generated and translated by AI from the official description.
The full analysis of this CVE is available in Portuguese →
goform/formEMR30 in Sumavision Enhanced Multimedia Router (EMR) 3.0.4.27 allows creation of arbitrary users with elevated privileges (administrator) on a device, as demonstrated by a setString=new_user<*1*>administrator<*1*>123456 request.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/apublic PoCs found — 1
cve_referencepacketstormsecurity.com/files/156746/Enhanced-Multimedia-Router-3.0.4.27-Cross-Site-Request-Forgery.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.