CVE-2020-36915

HIGH

Adtec Digital SignEdje <2.08.28 - Unauthenticated RCE

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-36915. PoCs published by LiquidWorm.

AI-analyzed exploit summary This writeup details default hardcoded credentials in multiple Adtec Digital products, allowing remote root access via SSH/Telnet. It lists affected versions and provides credential examples for authentication bypass.

Description

Adtec Digital SignEdje Digital Signage Player v2.08.28 contains multiple hardcoded default credentials that allow unauthenticated remote access to web, telnet, and SSH interfaces. Attackers can exploit these credentials to gain root-level access and execute system commands across multiple Adtec Digital product versions.

Exploits (1)

exploitdb WRITEUP
by LiquidWorm · textremotehardware
https://www.exploit-db.com/exploits/48954

This writeup details default hardcoded credentials in multiple Adtec Digital products, allowing remote root access via SSH/Telnet. It lists affected versions and provides credential examples for authentication bypass.

Classification
Writeup 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Adtec Digital Multiple Products (various versions)
No auth needed
Prerequisites: network access to the target device
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Exploit, Third Party Advisory exploit
https://www.exploit-db.com/exploits/48954
Various Sources product
https://www.adtecdigital.com
Third Party Advisory third-party-advisory
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5603.php
Third Party Advisory, VDB Entry vdb-entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/190628

Scores

CVSS v3 7.5
EPSS 0.0033
EPSS Percentile 24.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-1392 CWE-798
Status published
Published Jan 06, 2026
Tracked Since Feb 18, 2026