CVE-2020-36902: Medivision Digital Signage Firmware
Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.
UBICOD Medivision Digital Signage 1.5.1 contains an authorization bypass vulnerability that allows normal users to escalate privileges by manipulating the 'ft[grp]' parameter. Attackers can send a GET request to /html/user with 'ft[grp]' set to integer value '3' to gain super admin rights without authentication.
Affected products
- Medivision Medivision Digital Signage Firmware: version 1.5.1 only
Published 2025-12-10. Last modified 2026-06-17.