Skip to content
COOEY

EXPOSURES › CVE-2020-10181

CVE-2020-10181

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-10181 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 exploited-in-wildunpatchedrcesupply-chain

Sumavision EMR routers allow attackers to create admin accounts via CSRF, enabling full device control.

The Sumavision Enhanced Multimedia Router (EMR) contains a CSRF vulnerability that allows attackers to create administrator accounts without authentication. This failure is critical for DIB organizations because it grants remote, arbitrary code execution and full device control, directly impacting compliance with NIST 800-171 requirements for access control and system integrity. Organizations must ensure all network hardware is patched and monitored for unauthorized account creation.

Shame score — A known, actively exploited vulnerability in network hardware that allows attackers to bypass authentication and gain full administrative control, representing a severe negligence in patching and secure design.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Sumavision Enhanced Multimedia Router (EMR) contains a cross-site request forgery (CSRF) vulnerability allowing the creation of users with elevated privileges as administrator on a device.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Vulnerability allows privilege escalation; CISA KEV inclusion signals active exploitation, indicating severe fallout for Sumavision's security posture.
cooey ↗ severe-fallout -0.60
Neutral technical listing; no sentiment expressed, but vulnerability severity is inherent.
"Sumavision Enhanced Multimedia Router (EMR) contains a cross-site request forgery (CSRF) vulnerability allowing the creation of users with elevated privileges as administrator on a device."
recentbreaches.com ↗ severe-fallout +0.00
Irrelevant; no mention of Sumavision or CVE-2020-10181.
www.cvefind.com ↗ severe-fallout +0.00
Irrelevant; no mention of Sumavision or CVE-2020-10181.
vulnpedia.com ↗ severe-fallout +0.00
Irrelevant; no mention of Sumavision or CVE-2020-10181.
CISA ↗ severe-fallout +0.00
Irrelevant; no mention of Sumavision or CVE-2020-10181.
cvefeed.io ↗ severe-fallout +0.00
Irrelevant; no mention of Sumavision or CVE-2020-10181.
app.opencve.io ↗ severe-fallout +0.00
Irrelevant; no mention of Sumavision or CVE-2020-10181.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.