Howfor's vulnerability footprint concentrates in its Qihang Media Web digital signage product, with the durable signal centered on configuration and access-control weaknesses including backup-file exposure, path traversal, insufficiently protected credentials, and unrestricted dangerous-file uploads. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Howfor over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-36897CRITICAL QiHang Media Web Digital Signage 3.0.9 contains an unauthenticated remote code execution vulnerability in the QH.aspx file that allows attackers to upload malicious ASPX scripts. A | Dec 10, 2025 | 9.8 | 30 | NO | NO |
CVE-2020-36898CRITICAL QiHang Media Web Digital Signage 3.0.9 contains an unauthenticated file deletion vulnerability in the QH.aspx endpoint that allows remote attackers to delete files without authenti | Dec 10, 2025 | 9.1 | 29 | NO | NO |
CVE-2020-36899HIGH QiHang Media Web Digital Signage 3.0.9 contains an unauthenticated file disclosure vulnerability that allows remote attackers to access sensitive files through unverified 'filename | Dec 10, 2025 | 7.5 | 24 | NO | NO |
CVE-2020-36896HIGH QiHang Media Web Digital Signage 3.0.9 contains a cleartext credentials vulnerability that allows unauthenticated attackers to access administrative login information through an un | Dec 10, 2025 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Howfor.
Media articles that mention a CVE ID that affects a product developed by Howfor — matched by CVE ID, not by vendor name.