High severity7.5NVD Advisory· Published Dec 10, 2025· Updated Jun 17, 2026
CVE-2020-36896
CVE-2020-36896
Description
QiHang Media Web Digital Signage 3.0.9 contains a cleartext credentials vulnerability that allows unauthenticated attackers to access administrative login information through an unprotected XML file. Attackers can retrieve hardcoded admin credentials by requesting the '/xml/User/User.xml' file, enabling direct authentication bypass.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3<=3.0.9+ 1 more
- (no CPE)range: <=3.0.9
- (no CPE)range: =3.0.9
- cpe:2.3:a:howfor:qihang_media_web_digital_signage:3.0.9:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
4- www.exploit-db.com/exploits/48748nvdExploitThird Party AdvisoryVDB Entry
- www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5579.phpnvdExploitThird Party Advisory
- www.vulncheck.com/advisories/qihang-media-web-digital-signage-cleartext-credentials-disclosurenvdThird Party Advisory
- www.howfor.comnvdProduct
News mentions
0No linked articles in our index yet.