Unrated severityNVD Advisory· Published Dec 10, 2025· Updated Dec 11, 2025
QiHang Media Web Digital Signage 3.0.9 Cleartext Credentials Disclosure
CVE-2020-36896
Description
QiHang Media Web Digital Signage 3.0.9 contains a cleartext credentials vulnerability that allows unauthenticated attackers to access administrative login information through an unprotected XML file. Attackers can retrieve hardcoded admin credentials by requesting the '/xml/User/User.xml' file, enabling direct authentication bypass.
Affected products
1- Range: <=3.0.9
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- www.exploit-db.com/exploits/48748mitreexploit
- www.vulncheck.com/advisories/qihang-media-web-digital-signage-cleartext-credentials-disclosuremitrethird-party-advisory
- www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5579.phpmitrevendor-advisoryvdb-entry
- www.howfor.commitreproduct
News mentions
0No linked articles in our index yet.