CVE-2020-36914: Shenzhen Xingmeng Qihang Media Co., Ltd Qihang Media Web Qh.aspx Digital Signage

High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.

QiHang Media Web Digital Signage 3.0.9 contains a sensitive information disclosure vulnerability that allows remote attackers to intercept user authentication credentials through cleartext cookie transmission. Attackers can perform man-in-the-middle attacks to capture and potentially misuse stored authentication credentials transmitted in an insecure manner.

Affected products

Published 2026-01-06. Last modified 2026-06-17.