CVE-2020-36896: Howfor Qihang Media Web Digital Signage

High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.

QiHang Media Web Digital Signage 3.0.9 contains a cleartext credentials vulnerability that allows unauthenticated attackers to access administrative login information through an unprotected XML file. Attackers can retrieve hardcoded admin credentials by requesting the '/xml/User/User.xml' file, enabling direct authentication bypass.

Affected products

  • Howfor Qihang Media Web Digital Signage: version 3.0.9 only

Published 2025-12-10. Last modified 2026-06-17.