Description
Sony BRAVIA Digital Signage 1.7.8 contains a remote file inclusion vulnerability that allows attackers to inject arbitrary client-side scripts through the content material URL parameter. Attackers can exploit this vulnerability to hijack user sessions, execute cross-site scripting code, and modify display content by manipulating the input material type.
Published: 2026-01-06
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 26 Jan 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Thu, 22 Jan 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Sony bravia Signage
CPEs cpe:2.3:a:sony:bravia_signage:*:*:*:*:*:*:*:*
Vendors & Products Sony bravia Signage

Wed, 07 Jan 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Sony
Sony bravia
Sony bravia Tv
Vendors & Products Sony
Sony bravia
Sony bravia Tv

Tue, 06 Jan 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Jan 2026 16:00:00 +0000

Type Values Removed Values Added
Description Sony BRAVIA Digital Signage 1.7.8 contains a remote file inclusion vulnerability that allows attackers to inject arbitrary client-side scripts through the content material URL parameter. Attackers can exploit this vulnerability to hijack user sessions, execute cross-site scripting code, and modify display content by manipulating the input material type.
Title Sony BRAVIA Digital Signage 1.7.8 Unauthenticated Remote File Inclusion
Weaknesses CWE-829
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Sony Bravia Bravia Signage Bravia Tv
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-01-26T15:55:01.315Z

Reserved: 2026-01-03T14:10:13.302Z

Link: CVE-2020-36924

cve-icon Vulnrichment

Updated: 2026-01-06T18:20:19.283Z

cve-icon NVD

Status : Modified

Published: 2026-01-06T16:15:48.947

Modified: 2026-01-26T16:15:54.497

Link: CVE-2020-36924

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-01-07T10:08:41Z

Weaknesses