Description
A vulnerability was determined in Barco ClickShare CX-20 Gen2 up to 02.26.00.0007. Affected by this issue is some unknown functionality of the file /wallpaper of the component Wallpaper Upload. This manipulation of the argument wallpaper causes denial of service. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-28
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch ASAP
AI Analysis

Impact

The vulnerability lies in the wallpaper upload feature of Barco ClickShare CX-20 Gen2 devices. An attacker can manipulate the wallpaper argument to trigger an uncontrolled denial of service, causing the device to become unresponsive and disrupting availability for users. This weakness is classed as CWE-404, indicating improper handling of erroneous input.

Affected Systems

Barco ClickShare CX-20 Gen2 devices running firmware versions up to 02.26.00.0007 are affected. No other vendors or product lines are listed.

Risk and Exploitability

The CVSS score of 7.1 classifies the vulnerability as high severity. The EPSS score is not available, and it is not listed in the CISA KEV catalog, but the exploit has already been publicly disclosed. The remote attack vector is inferred from the mention of remote initiation; the attacker only needs network access to the device's /wallpaper endpoint to trigger the denial of service. Consequently, any user or administrator who relies on continuous availability of the device faces elevated risk of interruption.

Generated by OpenCVE AI on September 28, 2026 at 04:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the ClickShare CX-20 Gen2 firmware to a version newer than 02.26.00.0007, which resolves the denial‑of‑service issue in the wallpaper upload component.
  • Apply network segmentation or firewall rules to restrict external access to the ClickShare device, ensuring that only trusted hosts can reach the wallpaper upload interface.
  • If the device configuration allows, disable the wallpaper upload capability to eliminate the attack surface.

Generated by OpenCVE AI on September 28, 2026 at 04:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in Barco ClickShare CX-20 Gen2 up to 02.26.00.0007. Affected by this issue is some unknown functionality of the file /wallpaper of the component Wallpaper Upload. This manipulation of the argument wallpaper causes denial of service. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Title Barco ClickShare CX-20 Gen2 Wallpaper Upload wallpaper denial of service
First Time appeared Barco
Barco clickshare Cx-20 Gen2
Weaknesses CWE-404
CPEs cpe:2.3:a:barco:clickshare_cx-20_gen2:*:*:*:*:*:*:*:*
Vendors & Products Barco
Barco clickshare Cx-20 Gen2
References
Metrics cvssV2_0

{'score': 6.8, 'vector': 'AV:N/AC:L/Au:S/C:N/I:N/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Barco Clickshare Cx-20 Gen2
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-28T03:00:08.244Z

Reserved: 2026-09-27T08:54:38.088Z

Link: CVE-2026-100902

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T04:16:56.207

Modified: 2026-09-28T04:16:56.207

Link: CVE-2026-100902

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T04:30:18Z

Weaknesses
  • CWE-404

    Improper Resource Shutdown or Release