ReQuest Serious Play F3 Media Server versions 7.0.3.4968 (Pro), 7.0.2.4954, 6.5.2.4954, 6.4.2.4681, 6.3.2.4203, and 2.0.1.823 allows unauthenticated attackers to disclose the webserver's Python debug log file containing system information, credentials, paths, processes and command arguments running on the device. Attackers can access sensitive information by visiting the message_log page.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 05 Dec 2025 17:30:00 +0000

Type Values Removed Values Added
Description ReQuest Serious Play F3 Media Server versions 7.0.3.4968 (Pro), 7.0.2.4954, 6.5.2.4954, 6.4.2.4681, 6.3.2.4203, and 2.0.1.823 allows unauthenticated attackers to disclose the webserver's Python debug log file containing system information, credentials, paths, processes and command arguments running on the device. Attackers can access sensitive information by visiting the message_log page.
Title ReQuest Serious Play F3 Media Server <= 7.0.3 Debug Log Disclosure2020
Weaknesses CWE-532
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-12-05T20:07:14.638Z

Reserved: 2025-12-05T12:03:28.231Z

Link: CVE-2020-36876

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-12-05T18:15:53.207

Modified: 2025-12-05T18:15:53.207

Link: CVE-2020-36876

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses