← Vulnerability feed

Vulnerability record · CVE-2020-28330 · published 24 November 2020

CVE-2020-28330: Barco wepresent wipg-1600w firmware insufficiently protected credentials vulnerability

BBarco · Wepresent Wipg 1600w Firmware

Barco wePresent WiPG-1600W devices have Unprotected Transport of Credentials. Affected Version(s): 2.5.1.8. An attacker armed with hardcoded API credentials (retrieved by exploiting CVE-2020-28329) can issue an authenticated query to display the admin password for the main web user interface listening on port 443/tcp of a Barco wePresent WiPG-1600W device.

6.5 CVSS 3.1 Medium EPSS 1.2% · top 34.2% CWE-522 · Insufficiently protected credentials
6.5CVSS 3.1 base score, v2 4.0
1.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Barco wePresent WiPG-1600W devices have Unprotected Transport of Credentials. Affected Version(s): 2.5.1.8. An attacker armed with hardcoded API credentials (retrieved by exploiting CVE-2020-28329) can issue an authenticated query to display the admin password for the main web user interface listening on port 443/tcp of a Barco wePresent WiPG-1600W device.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-28330 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-3929Unauthenticated OS command injection in Crestron, Barco and other wireless presentation firmwareMultiple wireless presentation and collaboration devices (Crestron AM-100/AM-101, Barco wePresent, Extron ShareLink, Teq AV IT, SHARP, Optoma, Blackb…KEVEPSS 99%analysed9.8CVE-2020-28329Barco wepresent wipg-1600w firmware hard-coded credentials vulnerabilityBarco wePresent WiPG-1600W firmware includes a hardcoded API account and password that is discoverable by inspecting the firmware image. A malicious …EPSS 1.6%9.8CVE-2020-28332Barco wepresent wipg-1600w firmware download of code without integrity check vulnerabilityBarco wePresent WiPG-1600W devices download code without an Integrity Check. Affected Version(s): 2.5.1.8, 2.5.0.25, 2.5.0.24, 2.4.1.19. The Barco we…EPSS 1.1%9.8CVE-2020-28333Barco wepresent wipg-1600w firmware information exposure vulnerabilityBarco wePresent WiPG-1600W devices allow Authentication Bypass. Affected Version(s): 2.5.1.8. The Barco wePresent WiPG-1600W web interface does not u…EPSS 3.2%9.8CVE-2020-28334Barco wepresent wipg-1600w firmware hard-coded credentials vulnerabilityBarco wePresent WiPG-1600W devices use Hard-coded Credentials (issue 2 of 2). Affected Version(s): 2.5.1.8, 2.5.0.25, 2.5.0.24, 2.4.1.19. The Barco w…EPSS 4.8%9.8CVE-2019-3930Crestron am-100 firmware stack-based buffer overflow vulnerabilityThe Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W befo…EPSS 7.0%7.5CVE-2020-28331Barco wepresent wipg-1600w firmware vulnerabilityBarco wePresent WiPG-1600W devices have Improper Access Control. Affected Version(s): 2.5.1.8. The Barco wePresent WiPG-1600W device has an SSH daemo…EPSS 1.7%9.8CVE-2021-22681Rockwell Logix Designer authentication bypass via weak key verificationRockwell Automation Studio 5000 Logix Designer (v21+) and RSLogix 5000 (v16-20) rely on a key to verify that Logix controllers are talking to genuine…KEVEPSS 64%analysed

Source: NIST National Vulnerability Database (record CVE-2020-28330), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.