Remote File Inclusion Vulnerability in Sony BRAVIA Digital Signage
CVE-2020-36924
Key Information:
- Vendor
Pro-bravia
- Vendor
- CVE Published:
- 6 January 2026
Badges
What is CVE-2020-36924?
The Sony BRAVIA Digital Signage version 1.7.8 exhibits a significant vulnerability related to remote file inclusion. This flaw allows unauthorized users to inject arbitrary client-side scripts via the content material URL parameter. By exploiting this vulnerability, attackers can potentially hijack user sessions, perform cross-site scripting (XSS) attacks, and manipulate display content. Proper validation of user input and stringent security measures are crucial to mitigate the risks associated with this vulnerability.
Affected Version(s)
Sony BRAVIA Digital Signage 0 <= 1.7.8
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
