CVE-2024-7729: Cayin Technology CMS-20
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
The CAYIN Technology CMS lacks proper access control, allowing unauthenticated remote attackers to download arbitrary CGI files.
Affected products
- Cayin Technology CMS-20: version 11.0 only
- Cayin Technology CMS-60: version 11.0 only
- Cayin Technology CMS-SE: version 11.0 only
- Cayin Technology CMS-SE18.04: version 11.0 only
- Cayin Technology CMS-SE22.04: version 11.0 only
- Cayin Technology Smp-2100: version 3.0 only
- Cayin Technology Smp-2200: from 3.0, up to and including 4.0
- Cayin Technology Smp-2210: from 3.0, up to and including 4.0
- Cayin Technology Smp-2300: from 3.0, up to and including 4.0
- Cayin Technology Smp-2310: from 3.0, up to and including 4.0
- Cayin Technology Smp-2400: version 4.0 only
- Cayin Technology Smp-6000: version 3.0 only
- Cayin Technology Smp-8000: version 3.0 only
- Cayin Technology Smp-8000qd: version 3.0 only
- Cayin Technology Smp-8100: version 4.0 only
- Cayintech CMS-20: version 11.0 only
- Cayintech CMS-60: version 11.0 only
- Cayintech CMS-SE: version 11.0 only
- Cayintech CMS-se\18.04\: version 11.0 only
- Cayintech CMS-se\22.04\: version 11.0 only
- Cayintech Smp-2100: version 3.0 only
- Cayintech Smp-2200: from 3.0, up to and including 4.0
- Cayintech Smp-2210: from 3.0, up to and including 4.0
- Cayintech Smp-2300: from 3.0, up to and including 4.0
- Cayintech Smp-2310: from 3.0, up to and including 4.0
- and 5 more
Published 2024-08-14. Last modified 2026-06-17.