Sumavision EMR3.0 — CVE-2020-10181


Enhanced Multimedia Router version 3.0.4.27 suffers from a cross site request forgery vulnerability.

[Description]

goform/formEMR30 in Sumavision Enhanced Multimedia Router (EMR) 3.0.4.27 allows creation of arbitrary users with elevated privileges (administrator) on a device, as demonstrated by a setString=new_user<*1*>administrator<*1*>123456 request.

[Code]



[Demo Video]

https://www.youtube.com/watch?v=Ufcj4D9eA5o