Brightsign manufactures digital signage and media players, with its vulnerability exposure centered on the 4K242 hardware line and its associated firmware. The durable signal reflects web-facing and file-handling attack surfaces, with recurring weaknesses in path traversal and cross-site scripting that are typical of embedded web interfaces on networked devices. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Brightsign over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-17739CRITICAL The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) has directory traversal via the /storage.html rp parameter, allowing an attacker to read or write to files | Dec 18, 2017 | 9.8 | 46 | NO | YES |
CVE-2017-17738HIGH The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) allows renaming and modifying files via /tools.html. | Dec 18, 2017 | 7.5 | 36 | NO | YES |
CVE-2017-17737MEDIUM The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) has XSS via the REF parameter to /network_diagnostics.html or /storage_info.html. | Dec 18, 2017 | 6.1 | 31 | NO | YES |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Brightsign.
Media articles that mention a CVE ID that affects a product developed by Brightsign — matched by CVE ID, not by vendor name.