Spinetix develops digital signage and media-delivery platforms, including the Fusion product line and embedded firmware for signage appliances, with a vulnerability profile centered on web-facing and configuration interfaces. The recurring exposure reflects application-layer weaknesses common to internet-accessible control systems: path traversal, cleartext credential storage, cross-site request forgery, and server-side request forgery, each of which can compromise device integrity or enable lateral movement in networked deployments. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Spinetix over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-36886HIGH SpinetiX Fusion Digital Signage 3.4.8 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without proper request valida | Dec 10, 2025 | 8.8 | 27 | NO | NO |
CVE-2020-36883HIGH SpinetiX Fusion Digital Signage 3.4.8 and lower contains an authenticated path traversal vulnerability that allows attackers to manipulate file backup and deletion operations throu | Dec 10, 2025 | 8.1 | 25 | NO | NO |
CVE-2020-36887HIGH SpinetiX Fusion Digital Signage 3.4.8 contains an unauthenticated information disclosure vulnerability in the database backup directory. Attackers can access the /content/files/bac | Dec 10, 2025 | 7.5 | 24 | NO | NO |
CVE-2020-36888MEDIUM SpinetiX Fusion Digital Signage 3.4.8 contains a username enumeration vulnerability in its login script that allows attackers to identify valid user accounts. Attackers can send cr | Dec 10, 2025 | 5.3 | 19 | NO | NO |
CVE-2020-15809MEDIUM spxmanage on certain SpinetiX devices allows requests that access unintended resources because of SSRF and Path Traversal. This affects HMP350, HMP300, and DiVA through 4.5.2-1.0.3 | Mar 24, 2021 | 6.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Spinetix.
Media articles that mention a CVE ID that affects a product developed by Spinetix — matched by CVE ID, not by vendor name.