CVE-2025-54756
8.4BrightSign · BrightSign OS
BrightSign OS series 4 and 5 players contain a vulnerability where default passwords are guessable using device information, potentially allowing unauthorized access.
Executive summary
BrightSign digital signage players are vulnerable to unauthorized access due to the use of guessable default passwords, posing a significant risk to device integrity.
Vulnerability
The vulnerability involves the use of weak, guessable default credentials that can be exploited by an unauthenticated attacker with knowledge of basic device information to gain administrative control.
Business impact
The exploitation of this vulnerability could lead to total compromise of the affected digital signage players, allowing unauthorized actors to manipulate displayed content or pivot to other network segments. With a CVSS score of 8.4, this flaw represents a high risk to operational continuity and brand reputation, as compromised devices can be used to broadcast unauthorized information to public or internal audiences.
Remediation
Immediate Action: Update BrightSign OS to version 8.5.53.1 for series 4 players or version 9.0.166 for series 5 players immediately, and change all default passwords on existing installations.
Proactive Monitoring: Monitor device access logs for unusual login patterns or unauthorized configuration changes originating from unexpected internal network segments.
Compensating Controls: Ensure that all digital signage devices are isolated within a dedicated management VLAN and restricted by firewall rules to prevent unauthorized external or lateral network access.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high severity of this vulnerability, administrators must treat the remediation of these devices as a priority. Beyond applying the necessary firmware updates, organizations should enforce a strict policy of changing default credentials on all network-connected hardware to prevent future occurrences of this class of vulnerability.
Sources
Originally found and disclosed by Adam Merrill, a member of the Adversarial Modeling and Penetration Testing (AMPT) team at Sandia National Laboratories,, per the CVE Program record.