CVE-2020-36884
MEDIUMBrightSign Digital Signage Diagnostic Web Server <8.2.26 - SSRF
Title source: llmDescription
BrightSign Digital Signage Diagnostic Web Server 8.2.26 and less contains an unauthenticated server-side request forgery vulnerability in the 'url' GET parameter of the Download Speed Test service. Attackers can specify external domains to bypass firewalls and perform network enumeration by forcing the application to make arbitrary HTTP requests to internal network hosts.
Exploits (1)
References (5)
Scores
CVSS v4
6.9
EPSS
0.0008
EPSS Percentile
24.5%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-918
Status
published
Products (1)
BrightSign, LLC/BrightSign Digital Signage Diagnostic Web Server
< 8.2.26
Published
Dec 10, 2025
Tracked Since
Feb 18, 2026