Medivision's vulnerability profile centers on its digital signage platform and associated firmware, a narrowly scoped product line deployed in commercial and institutional display environments. The recurring weaknesses—cross-site request forgery and missing authorization checks—reflect common gaps in web-facing administrative interfaces typical of embedded and semi-embedded media management systems. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Medivision over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-36902CRITICAL UBICOD Medivision Digital Signage 1.5.1 contains an authorization bypass vulnerability that allows normal users to escalate privileges by manipulating the 'ft[grp]' parameter. Atta | Dec 10, 2025 | 9.8 | 30 | NO | NO |
CVE-2020-36901HIGH UBICOD Medivision Digital Signage 1.5.1 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without proper request vali | Dec 10, 2025 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Medivision.
Media articles that mention a CVE ID that affects a product developed by Medivision — matched by CVE ID, not by vendor name.