series 5 prior to v9.0.166 contain an execution with unnecessary
privileges vulnerability, allowing for privilege escalation on the
device once code execution has been obtained.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
BrightSign fixed CVE-2025-3925 https://www.cve.org/CVERecord in v8.5.53.1 (for series 4 players) and v9.0.166 (for series 5 players). Both of these have been released and available on the BrightSign download site. https://www.brightsign.biz/resources/software-downloads/ For more information, please contact BrightSign via their website. https://www.brightsign.biz/contact-us/
Vendor Workaround
BrightSign recommends the following security practices: * Change default passwords when the device is initially set up. * Disable the local DWS as described in "High Security settings". * Disable the SSH/telnet server when not being used - it is not enabled by default. * Devices should be located where an attacker does not have physical access to the device. * SD and USB ports can be disabled if not needed. For more information, please contact BrightSign via their website. https://www.brightsign.biz/contact-us/
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-13932 | BrightSign players running BrightSign OS series 4 prior to v8.5.53.1 or series 5 prior to v9.0.166 contain an execution with unnecessary privileges vulnerability, allowing for privilege escalation on the device once code execution has been obtained. |
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 08 May 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 07 May 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | BrightSign players running BrightSign OS series 4 prior to v8.5.53.1 or series 5 prior to v9.0.166 contain an execution with unnecessary privileges vulnerability, allowing for privilege escalation on the device once code execution has been obtained. | |
| Title | BrightSign Players Execution with Unnecessary Privileges | |
| Weaknesses | CWE-250 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-05-08T14:04:48.853Z
Reserved: 2025-04-24T17:54:29.059Z
Link: CVE-2025-3925
Updated: 2025-05-08T14:04:45.517Z
Status : Deferred
Published: 2025-05-07T21:16:03.897
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-3925
No data.
OpenCVE Enrichment
No data.
EUVD