CVE-2020-36876
HIGHReQuest Serious Play F3 Media Server <7.0.3.4968 - Info Disclosure
Title source: llmDescription
ReQuest Serious Play F3 Media Server versions 7.0.3.4968 (Pro), 7.0.2.4954, 6.5.2.4954, 6.4.2.4681, 6.3.2.4203, and 2.0.1.823 allows unauthenticated attackers to disclose the webserver's Python debug log file containing system information, credentials, paths, processes and command arguments running on the device. Attackers can access sensitive information by visiting the message_log page.
Exploits (1)
References (4)
Scores
CVSS v4
8.7
EPSS
0.0013
EPSS Percentile
32.4%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-532
Status
published
Products (6)
ReQuest Serious Play LLC/ReQuest Serious Play
2.0.1.823
ReQuest Serious Play LLC/ReQuest Serious Play
6.3.2.4203
ReQuest Serious Play LLC/ReQuest Serious Play
6.4.2.4681
ReQuest Serious Play LLC/ReQuest Serious Play
6.5.2.4954
ReQuest Serious Play LLC/ReQuest Serious Play
7.0.2.4954
ReQuest Serious Play LLC/ReQuest Serious Play Pro
7.0.3.4968
Published
Dec 05, 2025
Tracked Since
Feb 18, 2026