BrightSign Digital Signage Diagnostic Web Server 8.2.26 and less contains an unauthenticated server-side request forgery vulnerability in the 'url' GET parameter of the Download Speed Test service. Attackers can specify external domains to bypass firewalls and perform network enumeration by forcing the application to make arbitrary HTTP requests to internal network hosts.
Metrics
Affected Vendors & Products
References
History
Thu, 11 Dec 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Brightsign
Brightsign digital Signage Diagnostic Web Server |
|
| Vendors & Products |
Brightsign
Brightsign digital Signage Diagnostic Web Server |
Thu, 11 Dec 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 10 Dec 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | BrightSign Digital Signage Diagnostic Web Server 8.2.26 and less contains an unauthenticated server-side request forgery vulnerability in the 'url' GET parameter of the Download Speed Test service. Attackers can specify external domains to bypass firewalls and perform network enumeration by forcing the application to make arbitrary HTTP requests to internal network hosts. | |
| Title | BrightSign Digital Signage Diagnostic Web Server 8.2.26 Unauthenticated SSRF | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-12-10T20:47:43.331Z
Updated: 2025-12-11T18:53:57.677Z
Reserved: 2025-12-09T11:05:19.895Z
Link: CVE-2020-36884
Updated: 2025-12-11T16:04:16.465Z
Status : Awaiting Analysis
Published: 2025-12-10T21:16:00.650
Modified: 2025-12-12T15:18:42.140
Link: CVE-2020-36884
No data.