CVE-2020-36922

HIGH

Sony BRAVIA Digital Signage <1.7.8 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-36922. PoCs published by LiquidWorm.

AI-analyzed exploit summary This exploit demonstrates an unauthenticated information disclosure vulnerability in Sony BRAVIA Digital Signage 1.7.8. It leverages an exposed API endpoint to retrieve sensitive system information, including network interfaces, server time, and OS details.

Description

Sony BRAVIA Digital Signage 1.7.8 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive system details through API endpoints. Attackers can retrieve network interface information, server configurations, and system metadata by sending requests to the exposed system API.

Exploits (1)

exploitdb WORKING POC
by LiquidWorm · textwebappshardware
https://www.exploit-db.com/exploits/49187

This exploit demonstrates an unauthenticated information disclosure vulnerability in Sony BRAVIA Digital Signage 1.7.8. It leverages an exposed API endpoint to retrieve sensitive system information, including network interfaces, server time, and OS details.

Classification
Working Poc 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Sony BRAVIA Digital Signage <=1.7.8
No auth needed
Prerequisites: Network access to the target device · API endpoint exposed on port 8080
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 7.5
EPSS 0.0055
EPSS Percentile 41.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-497
Status published
Products (1)
sony/bravia_signage < 1.7.8
Published Jan 06, 2026
Tracked Since Feb 18, 2026