Impact
The vulnerability lies in the wallpaper upload feature of Barco ClickShare CX-20 Gen2 devices. An attacker can manipulate the wallpaper argument to trigger an uncontrolled denial of service, causing the device to become unresponsive and disrupting availability for users. This weakness is classed as CWE-404, indicating improper handling of erroneous input.
Affected Systems
Barco ClickShare CX-20 Gen2 devices running firmware versions up to 02.26.00.0007 are affected. No other vendors or product lines are listed.
Risk and Exploitability
The CVSS score of 7.1 classifies the vulnerability as high severity. The EPSS score is not available, and it is not listed in the CISA KEV catalog, but the exploit has already been publicly disclosed. The remote attack vector is inferred from the mention of remote initiation; the attacker only needs network access to the device's /wallpaper endpoint to trigger the denial of service. Consequently, any user or administrator who relies on continuous availability of the device faces elevated risk of interruption.
OpenCVE Enrichment