CVE-2020-36914
7.5Shenzhen Xingmeng Qihang Media Co., Ltd. · QiHang Media Web Digital Signage
QiHang Media Web Digital Signage 3.0.9.0 transmits authentication cookies in cleartext, allowing remote attackers to intercept credentials via man-in-the-middle attacks.
Executive summary
A critical vulnerability in QiHang Media Web Digital Signage 3.0.9.0 permits unauthenticated attackers to intercept user credentials through cleartext cookie transmission.
Vulnerability
The software fails to secure sensitive authentication data during transmission, resulting in cleartext cookie exposure. This allows an unauthenticated attacker positioned on the same network segment to perform man-in-the-middle attacks and hijack active user sessions.
Business impact
Successful exploitation of this vulnerability allows unauthorized actors to intercept administrative or user credentials, leading to full account takeover. Given the nature of digital signage systems, this could result in unauthorized content modification, reputational damage, or the potential for lateral movement into internal networks. The CVSS score of 7.5 reflects the high impact on confidentiality and integrity, necessitating urgent attention to mitigate the risk of credential theft.
Remediation
Immediate Action: Since no official patch is currently available, restrict access to the web interface to trusted management networks only and enforce mandatory VPN usage for all remote administrative access.
Proactive Monitoring: Monitor network traffic for suspicious interception patterns or unauthorized access attempts to the management interface. Review server logs for anomalous login activity that may indicate session hijacking.
Compensating Controls: Deploy a Web Application Firewall (WAF) or an internal proxy that enforces mandatory TLS encryption for all traffic, effectively wrapping the insecure cleartext communication in a secure transport layer.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists, attributed to the research documentation hosted on Packet Storm Security.
Analyst recommendation
This vulnerability poses a significant risk to organizational integrity due to the ease with which credentials can be harvested. Because no vendor patch is available, administrators must prioritize network-level isolation and the implementation of forced encryption via proxy or WAF solutions. Organizations should evaluate the necessity of the web-based management interface and limit its exposure to the public internet immediately to prevent exploitation.
More Shenzhen Xingmeng Qihang Media Co., Ltd. CVEs
Sources
Originally found and disclosed by LiquidWorm as Gjoko Krstic of Zero Science Lab, per the CVE Program record.
- Zero Science Lab Disclosure (ZSL-2020-5578) Third-party advisory
- Packet Storm Security Exploit Entry Exploit / PoC
- IBM X-Force Vulnerability Exchange Vulnerability database entry
- CXSecurity Vulnerability Database Entry Third-party advisory
- HowFor Vendor Homepage
- VulnCheck Advisory: QiHang Media Web Digital Signage 3.0.9 Cookie Authentication Credentials Disclosure Third-party advisory