Back

HIGH

QiHang Media Web Digital Signage 3.0.9 Unauthenticated Arbitrary File Disclosure

Published Dec 10, 2025

Description

QiHang Media Web Digital Signage 3.0.9 contains an unauthenticated file disclosure vulnerability that allows remote attackers to access sensitive files through unverified 'filename' and 'path' parameters. Attackers can exploit the QH.aspx endpoint to read arbitrary files and directory contents without authentication by manipulating download and getAll actions.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (5)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner VulnCheck
Published Dec 10, 2025
Updated Dec 11, 2025
Reserved Dec 9, 2025

CISA Vulnrichment

Updated Dec 11, 2025

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner VulnCheck
Published Dec 10, 2025
Updated Dec 11, 2025

GitHub

No data