HIGH
QiHang Media Web Digital Signage 3.0.9 Unauthenticated Arbitrary File Disclosure
Published Dec 10, 2025
8.7
HIGHCVSS 4.0
EPSS 0.92%
Description
QiHang Media Web Digital Signage 3.0.9 contains an unauthenticated file disclosure vulnerability that allows remote attackers to access sensitive files through unverified 'filename' and 'path' parameters. Attackers can exploit the QH.aspx endpoint to read arbitrary files and directory contents without authentication by manipulating download and getAll actions.
Affected products
- Vendor n/a Product QiHang Media Web Digital Signage Defaultunaffected
Affected
- 3.0.9.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | QiHang Media Web Digital Signage | unaffected | Affected
|
- 3.0.9
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- http://www.howfor.com product
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-30833 Advisory
- https://www.exploit-db.com/exploits/48750 exploitThird Party AdvisoryVDB Entry
- https://www.vulncheck.com/advisories/qihang-media-web-digital-signage-unauthenticated-arbitrary-file-disclosure third-party-advisoryThird Party Advisory
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5581.php exploitvendor-advisoryvdb-entryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.howfor.com | product | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-30833 | Advisory | |
| https://www.exploit-db.com/exploits/48750 | exploitThird Party AdvisoryVDB Entry | |
| https://www.vulncheck.com/advisories/qihang-media-web-digital-signage-unauthenticated-arbitrary-file-disclosure | third-party-advisoryThird Party Advisory | |
| https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5581.php | exploitvendor-advisoryvdb-entryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Dec 10, 2025
Updated Dec 11, 2025
Reserved Dec 9, 2025
Link CVE-2020-36899
CISA Vulnrichment
Updated Dec 11, 2025
Red Hat
No data
GitHub
No data