CVE detail
CVE-2020-36899 — CVE-2020-36899
Published 2025-12-10 · Modified 2026-06-17 · Vendor howfor · Product qihang_media_web_digital_signage · Source nvd
HIGH
severity
CVSS-derived band
0.0094
EPSS probability
exploitation probability, 30d
58.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
QiHang Media Web Digital Signage 3.0.9 contains an unauthenticated file disclosure vulnerability that allows remote attackers to access sensitive files through unverified 'filename' and 'path' parameters. Attackers can exploit the QH.aspx endpoint to read arbitrary files and directory contents without authentication by manipulating download and getAll actions.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References