Friday, December 15, 2017

BrightSign - Multiple Vulnerablities - CVE-2017-17737, 17738, 17739

The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) suffers from multiple vulnerabilities.

The pages:


Suffer from a Cross-Site Scripting vulnerability. The REF parameter for these pages do not sanitize user input, resulting in arbitrary execution, token theft and related attacks.

The RP parameter in STORAGE.HTML suffers from a directory traversal/information leakage weakness:

Through parameter manipulation, the file system can be traversed, unauthenticated, allowing for leakage of information and compromise of the device.

This page also allows for unauthenticated upload of files.


Page allows for unauthenticated rename/manipulation of files.

When combined, these vulnerabilities allow for compromise of both end users and the device itself.

Ex. A malicious attacker can upload a malicious page of their choosing and steal credentials, host malicious content or distribute content through the device, which accepts large format SD cards.


  1. Proper security procedures are posted in detail on the BrightSign documentation website.
    These additional vulnerability issues have been resolved in 6.2.171 and newer.

  2. Selecting a digital signage screen or system for your business includes several components such as software and hardware management, fees, types of screens, security, pricing, and flexibility of the contract. Choosing the right system will aid in how much the signage benefits the business.  digital signage software

  3. Signage is always a useful thing. Because by this thing people find their place so easily. Life is getting very easier by this Signage Perth.

  4. I have read your blog it is very helpful for us. I couldn't find any knowledge on this matter prior to. I would like to thanks for sharing this article here. If anyone looking for the Digital Signage Companies in Dubai, Visit rizqgroup

  5. Really helpful, if you looking for Digital Signage Manufacturer and Supplier
    in Dubai then connect with Universal Media House.

  6. I liked your work and, as a result, the manner you presented this content about Digital Signs For Businesses In Ireland.It is a valuable paper for us. Thank you for sharing this blog with us.

  7. Signboard company in Dubai many of our customers choose iDesignads because of our best prices which is really stands out form the other signboard companies in Dubai. We have 10+ years of experience in signboard industry which makes every customer trust worthy option. Choose wisely, and get ready to watch your business light up the Dubai skyline
    For more info Visit our website