CVE detail
CVE-2020-36902 — CVE-2020-36902
Published 2025-12-10 · Modified 2026-06-17 · Vendor medivision · Product medivision_digital_signage_firmware · Source nvd
CRITICAL
severity
CVSS-derived band
0.0115
EPSS probability
exploitation probability, 30d
64.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
UBICOD Medivision Digital Signage 1.5.1 contains an authorization bypass vulnerability that allows normal users to escalate privileges by manipulating the 'ft[grp]' parameter. Attackers can send a GET request to /html/user with 'ft[grp]' set to integer value '3' to gain super admin rights without authentication.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References