VYPR

BrightSign OS

by BrightSign

CVEs (3)

  • CVE-2025-54756HigFeb 12, 2026
    risk 0.55cvss 8.4epss 0.00

    BrightSign players running BrightSign OS series 4 prior to v8.5.53.1 or series 5 prior to v9.0.166 use a default password that is guessable with knowledge of the device information. The latest release fixes this issue for new installations; users of old installations are encouraged to change all default passwords.

  • CVE-2025-3925HigMay 7, 2025
    risk 0.51cvss 7.8epss 0.00

    BrightSign players running BrightSign OS series 4 prior to v8.5.53.1 or series 5 prior to v9.0.166 contain an execution with unnecessary privileges vulnerability, allowing for privilege escalation on the device once code execution has been obtained.

  • CVE-2020-36884MedDec 10, 2025
    risk 0.45cvss epss 0.00

    BrightSign Digital Signage Diagnostic Web Server 8.2.26 and less contains an unauthenticated server-side request forgery vulnerability in the 'url' GET parameter of the Download Speed Test service. Attackers can specify external domains to bypass firewalls and perform network enumeration by forcing the application to make arbitrary HTTP requests to internal network hosts.