PT-2025-49270 · Unknown · Request Serious Play F3 Media Server

Published

2025-12-05

·

Updated

2025-12-05

·

CVE-2020-36876

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions ReQuest Serious Play F3 Media Server versions 2.0.1.823 through 7.0.3.4968
Description An unauthenticated attacker can access the webserver's Python debug log file. This log file contains system information, credentials, paths, processes, and command arguments running on the device. The attacker can access this information by visiting the message log page.
Recommendations Update to a newer version that contains a fix for this vulnerability. Update version 2.0.1.823. Update version 6.3.2.4203. Update version 6.4.2.4681. Update version 6.5.2.4954. Update version 7.0.2.4954. Update version 7.0.3.4968.

Exploit

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

CVE-2020-36876

Affected Products

Request Serious Play F3 Media Server