CVE-2020-36917: Guangzhou Yeroo Tech Co., Ltd IDS6 Dsspro Digital Signage System
High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.
iDS6 DSSPro Digital Signage System 6.2 contains a sensitive information disclosure vulnerability that allows remote attackers to intercept authentication credentials through cleartext cookie transmission. Attackers can exploit the autoSave feature to capture user passwords during man-in-the-middle attacks on HTTP communications.
Affected products
- Guangzhou Yeroo Tech Co., Ltd IDS6 Dsspro Digital Signage System: version V6.2 B2014.12.12.1220 only; version V5.6 B2017.07.12.1757 only; version V4.3 only
Published 2026-01-06. Last modified 2026-06-17.