CVE-2020-36902
CRITICALUBICOD Medivision Digital Signage 1.5.1 - Auth Bypass
Title source: llmDescription
UBICOD Medivision Digital Signage 1.5.1 contains an authorization bypass vulnerability that allows normal users to escalate privileges by manipulating the 'ft[grp]' parameter. Attackers can send a GET request to /html/user with 'ft[grp]' set to integer value '3' to gain super admin rights without authentication.
Exploits (1)
References (4)
Scores
CVSS v3
9.8
EPSS
0.0066
EPSS Percentile
71.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-862
Status
published
Products (1)
medivision/medivision_digital_signage_firmware
1.5.1
Published
Dec 10, 2025
Tracked Since
Feb 18, 2026