CVE-2020-36902

CRITICAL

UBICOD Medivision Digital Signage 1.5.1 - Auth Bypass

Title source: llm

Description

UBICOD Medivision Digital Signage 1.5.1 contains an authorization bypass vulnerability that allows normal users to escalate privileges by manipulating the 'ft[grp]' parameter. Attackers can send a GET request to /html/user with 'ft[grp]' set to integer value '3' to gain super admin rights without authentication.

Exploits (1)

exploitdb WORKING POC
by LiquidWorm · textwebappshardware
https://www.exploit-db.com/exploits/48684

Scores

CVSS v3 9.8
EPSS 0.0066
EPSS Percentile 71.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-862
Status published
Products (1)
medivision/medivision_digital_signage_firmware 1.5.1
Published Dec 10, 2025
Tracked Since Feb 18, 2026