CVE detail
CVE-2020-36896 — CVE-2020-36896
Published 2025-12-10 · Modified 2026-06-17 · Vendor howfor · Product qihang_media_web_digital_signage · Source nvd
HIGH
severity
CVSS-derived band
0.0089
EPSS probability
exploitation probability, 30d
56.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
QiHang Media Web Digital Signage 3.0.9 contains a cleartext credentials vulnerability that allows unauthenticated attackers to access administrative login information through an unprotected XML file. Attackers can retrieve hardcoded admin credentials by requesting the '/xml/User/User.xml' file, enabling direct authentication bypass.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References