CVE-2020-36915
Severity CVSS v4.0:
HIGH
Type:
CWE-798
Use of Hard-coded Credentials
Publication date:
06/01/2026
Last modified:
06/01/2026
Description
Adtec Digital SignEdje Digital Signage Player v2.08.28 contains multiple hardcoded default credentials that allow unauthenticated remote access to web, telnet, and SSH interfaces. Attackers can exploit these credentials to gain root-level access and execute system commands across multiple Adtec Digital product versions.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
7.50
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- https://exchange.xforce.ibmcloud.com/vulnerabilities/190628
- https://packetstorm.news/files/id/159709
- https://www.adtecdigital.com
- https://www.exploit-db.com/exploits/48954
- https://www.vulncheck.com/advisories/adtec-digital-signedje-digital-signage-player-default-credentials
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5603.php
- https://www.exploit-db.com/exploits/48954



