EXPOSURES › CVE-2020-10181
CVE-2020-10181
HIGH ⌖ ON CISA KEV · EXPLOITEDSumavision EMR routers allow attackers to create admin accounts via CSRF, enabling full device control.
The Sumavision Enhanced Multimedia Router (EMR) contains a CSRF vulnerability that allows attackers to create administrator accounts without authentication. This failure is critical for DIB organizations because it grants remote, arbitrary code execution and full device control, directly impacting compliance with NIST 800-171 requirements for access control and system integrity. Organizations must ensure all network hardware is patched and monitored for unauthorized account creation.
Shame score — A known, actively exploited vulnerability in network hardware that allows attackers to bypass authentication and gain full administrative control, representing a severe negligence in patching and secure design.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Sumavision Enhanced Multimedia Router (EMR) contains a cross-site request forgery (CSRF) vulnerability allowing the creation of users with elevated privileges as administrator on a device.
"Sumavision Enhanced Multimedia Router (EMR) contains a cross-site request forgery (CSRF) vulnerability allowing the creation of users with elevated privileges as administrator on a device."