Vulnerability record · CVE-2020-28331 · published 24 November 2020
CVE-2020-28331: Barco wepresent wipg-1600w firmware vulnerability
BBarco · Wepresent Wipg 1600w Firmware
Barco wePresent WiPG-1600W devices have Improper Access Control. Affected Version(s): 2.5.1.8. The Barco wePresent WiPG-1600W device has an SSH daemon included in the firmware image. By default, the SSH daemon is disabled and does not start at system boot. The system initialization scripts read a device configuration file variable to see if the SSH daemon should be started. The web interface does not provide a visible capability to alter this configuration file variable. However, a malicious actor can include this variable in a POST such that the SSH daemon will be started when the device boots.
Description
Barco wePresent WiPG-1600W devices have Improper Access Control. Affected Version(s): 2.5.1.8. The Barco wePresent WiPG-1600W device has an SSH daemon included in the firmware image. By default, the SSH daemon is disabled and does not start at system boot. The system initialization scripts read a device configuration file variable to see if the SSH daemon should be started. The web interface does not provide a visible capability to alter this configuration file variable. However, a malicious actor can include this variable in a POST such that the SSH daemon will be started when the device boots.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/160162/Barco-wePresent-Undocumented-SSH-Interface.html | Third Party AdvisoryVDB Entry |
| https://korelogic.com/Resources/Advisories/KL-001-2020-007.txt | Third Party Advisory |
| http://packetstormsecurity.com/files/160162/Barco-wePresent-Undocumented-SSH-Interface.html | Third Party AdvisoryVDB Entry |
| https://korelogic.com/Resources/Advisories/KL-001-2020-007.txt | Third Party Advisory |
Track CVE-2020-28331 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-28331), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.