Adtec Digital SignEdje Digital Signage Player v2.08.28 contains multiple hardcoded default credentials that allow unauthenticated remote access to web, telnet, and SSH interfaces. Attackers can exploit these credentials to gain root-level access and execute system commands across multiple Adtec Digital product versions.
History

Tue, 06 Jan 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Jan 2026 16:00:00 +0000

Type Values Removed Values Added
Description Adtec Digital SignEdje Digital Signage Player v2.08.28 contains multiple hardcoded default credentials that allow unauthenticated remote access to web, telnet, and SSH interfaces. Attackers can exploit these credentials to gain root-level access and execute system commands across multiple Adtec Digital product versions.
Title Adtec Digital SignEdje Digital Signage Player v2.08.28 Default Credentials
Weaknesses CWE-1392
CWE-798
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-01-06T19:42:42.982Z

Reserved: 2026-01-03T14:10:13.301Z

Link: CVE-2020-36915

cve-icon Vulnrichment

Updated: 2026-01-06T19:42:33.475Z

cve-icon NVD

Status : Received

Published: 2026-01-06T16:15:47.550

Modified: 2026-01-06T20:15:44.150

Link: CVE-2020-36915

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.