CVE-2018-14573: Trms Tightrope Media Carousel Digital Signage

Medium severity, CVSS 5.5. EPSS: 6.4% chance of exploitation in the next 30 days.

A Local File Inclusion (LFI) vulnerability exists in the Web Interface API of TightRope Media Carousel Digital Signage before 7.3.5. The RenderingFetch API allows for the downloading of arbitrary files through the use of directory traversal sequences, aka CSL-1683.

Affected products

  • Trms Tightrope Media Carousel Digital Signage: before 7.3.5 (fixed in 7.3.5)

Published 2018-07-23. Last modified 2026-06-17.