Default Credentials Vulnerability in Adtec Digital SignEdje Digital Signage Player
CVE-2020-36915
Key Information:
- Vendor
Adtecdigital
- Status
- Vendor
- CVE Published:
- 6 January 2026
Badges
What is CVE-2020-36915?
Adtec Digital SignEdje Digital Signage Player v2.08.28 is vulnerable due to multiple hardcoded default credentials. This design flaw enables unauthenticated remote access to the web, telnet, and SSH interfaces. Malicious actors can exploit these hardcoded credentials to gain root-level access, potentially leading to execution of arbitrary system commands across various Adtec Digital product versions.
Affected Version(s)
adManage Traffic & Media Management Application 2.5.4
afiniti Multi-Carrier Platform 1905_11
ED-71 10-bit / 1080p Integrated Receiver Decoder 2.02.24
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
