Unauthenticated Privilege Escalation in Eibiz i-Media Server Digital Signage by Eibiz
CVE-2020-36892
Key Information:
- Vendor
Eibiz Co.,ltd.
- Vendor
- CVE Published:
- 10 December 2025
Badges
What is CVE-2020-36892?
The Eibiz i-Media Server Digital Signage version 3.8.0 is susceptible to an unauthenticated privilege escalation vulnerability. This flaw exists within the updateUser object and allows malicious actors to exploit the /messagebroker/amf endpoint. By manipulating user role settings without requiring any form of authentication, attackers can elevate privileges and unlawfully take over user accounts, posing significant risks to system integrity and data security.
Affected Version(s)
i-Media Server Digital Signage 0 <= 3.8.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
