QiHang Media Web Digital Signage Credential Disclosure Scanner

Targets the web interface's configuration endpoint where credentials are stored in plaintext, allowing attackers to extract admin login details.

Short Info


Level

High

Single Scan

Single Scan

Can be used by

Asset Owner

Estimated Time

10 seconds

Time Interval

19 days 15 hours

Scan only one

URL

Toolbox

QiHang Media Web Digital Signage is a platform used by organizations to manage and deploy digital signage content across multiple screens. Marketing teams, IT administrators, and service providers rely on it to schedule and display multimedia in retail stores, corporate offices, and public venues. The software offers remote management via a web interface, enabling users to update content in real-time.

The credential disclosure vulnerability arises when the application stores administrative credentials in plaintext within configuration files or transmits them over unencrypted channels. This occurs due to inadequate security practices during development, such as hardcoding passwords or failing to implement encryption for sensitive data. Attackers can exploit this by accessing exposed endpoints or intercepting network traffic.

Specifically, the vulnerability affects the /config endpoint in QiHang Media Web Digital Signage version 3.0.9, where credentials are stored in a JSON file without encryption. By sending a GET request to this endpoint, an attacker can retrieve the admin username and password in plaintext. No authentication is required to access this sensitive data.

If exploited, an attacker gains full administrative access to the digital signage system, allowing them to modify displayed content, disrupt operations, or deploy malicious media. This can lead to reputational damage, financial loss, or physical security risks in public spaces. The high CVSS score of 8.3 reflects the critical nature of this vulnerability.

Get started to protecting your digital assets