Executive brief
CAYIN's CMS-WS, CMS-SE, and SMP series are content management and streaming products used to deliver media and manage digital assets. An authenticated attacker with administrative privileges can upload arbitrary files and execute web shell backdoors on the server, potentially leading to complete system compromise and unauthorized access to all data.
Technical details
This is an arbitrary file upload vulnerability in CAYIN CMS-WS, CMS-SE, and SMP products that allows privileged remote attackers (those with administrative credentials) to upload and execute malicious files. The vulnerability enables attackers to upload web shells and backdoors, achieving arbitrary code execution on the server. The attack vector is network-based and requires high-level administrative privileges. Patches are available: CMS-WS should be updated to version 1.0.26198 or later, CMS-SE to 11.0.26198 or later, and SMP to 4.0.26198 or later.
Affected products
- CAYIN Technology CMS-WS 1.0.25336 and earlier
- CAYIN Technology CMS-SE 11.0.25336 and earlier
- CAYIN Technology SMP 4.0.25336 and earlier
Timeline
- 2026-08-26: disclosed