Authentication Bypass in Eibiz i-Media Server Digital Signage
CVE-2020-36894
Key Information:
- Vendor
Eibiz Co.,ltd.
- Vendor
- CVE Published:
- 10 December 2025
Badges
What is CVE-2020-36894?
The Eibiz i-Media Server Digital Signage version 3.8.0 is susceptible to an authentication bypass vulnerability, which permits unauthorized attackers to create administrative users remotely. By manipulating AMF-encoded serialized objects and sending them to the /messagebroker/amf endpoint, attackers can bypass all security measures. This vulnerability poses a significant risk as it allows malicious entities to gain administrative access without proper credentials.
Affected Version(s)
i-Media Server Digital Signage 0 <= 3.8.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
