# CVE-2020-36921

## Summary

- **CVE ID:** CVE-2020-36921
- **Severity:** MEDIUM
- **CVSS Score:** 7.5 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-548
- **Published:** Jan 6, 2026
- **Last Modified:** Mar 14, 2026

## Description

RED-V Super Digital Signage System 5.1.1 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive webserver log files. Attackers can visit multiple endpoints to retrieve system resources and debug log information without authentication.

## Affected Products

- RED — RED-V Super Digital Signage System RXV-A740R (5.1.1)

## References

- [CNA](https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5609.php)
- [CNA](https://packetstormsecurity.com/files/160073)
- [CNA](https://exchange.xforce.ibmcloud.com/vulnerabilities/191803)
- [CNA](https://cxsecurity.com/issue/WLB-2020110130)
- [CNA](https://www.red-v.tv/)
- [CNA](https://www.vulncheck.com/advisories/red-v-super-digital-signage-system-log-information-disclosure-vulnerability)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.25%
- **EPSS Percentile:** 47.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._