CVE-2025-3925

HIGH

BrightSign OS <8.5.53.1-9.0.166 - Privilege Escalation

Title source: llm
STIX 2.1

Description

BrightSign players running BrightSign OS series 4 prior to v8.5.53.1 or series 5 prior to v9.0.166 contain an execution with unnecessary privileges vulnerability, allowing for privilege escalation on the device once code execution has been obtained.

Scores

CVSS v3 7.8
EPSS 0.0008
EPSS Percentile 23.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-250
Status published
Products (2)
BrightSign/BrightSign OS series 4 players < v8.5.53.1
BrightSign/BrightSign OS series 5 players < v9.0.166
Published May 07, 2025
Tracked Since Feb 18, 2026