← Vulnerability feed

Vulnerability record · CVE-2020-28333 · published 24 November 2020

CVE-2020-28333: Barco wepresent wipg-1600w firmware information exposure vulnerability

BBarco · Wepresent Wipg 1600w Firmware

Barco wePresent WiPG-1600W devices allow Authentication Bypass. Affected Version(s): 2.5.1.8. The Barco wePresent WiPG-1600W web interface does not use session cookies for tracking authenticated sessions. Instead, the web interface uses a "SEID" token that is appended to the end of URLs in GET requests. Thus the "SEID" would be exposed in web proxy logs and browser history. An attacker that is able to capture the "SEID" and originate requests from the same IP address (via a NAT device or web proxy) would be able to access the user interface of the device without having to know the credentials.

9.8 CVSS 3.1 Critical EPSS 3.2% · top 12.2% CWE-200 · Information exposureCWE-287 · Improper authentication
9.8CVSS 3.1 base score, v2 7.5
3.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Barco wePresent WiPG-1600W devices allow Authentication Bypass. Affected Version(s): 2.5.1.8. The Barco wePresent WiPG-1600W web interface does not use session cookies for tracking authenticated sessions. Instead, the web interface uses a "SEID" token that is appended to the end of URLs in GET requests. Thus the "SEID" would be exposed in web proxy logs and browser history. An attacker that is able to capture the "SEID" and originate requests from the same IP address (via a NAT device or web proxy) would be able to access the user interface of the device without having to know the credentials.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-28333 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-3929Unauthenticated OS command injection in Crestron, Barco and other wireless presentation firmwareMultiple wireless presentation and collaboration devices (Crestron AM-100/AM-101, Barco wePresent, Extron ShareLink, Teq AV IT, SHARP, Optoma, Blackb…KEVEPSS 99%analysed9.8CVE-2020-28329Barco wepresent wipg-1600w firmware hard-coded credentials vulnerabilityBarco wePresent WiPG-1600W firmware includes a hardcoded API account and password that is discoverable by inspecting the firmware image. A malicious …EPSS 1.6%9.8CVE-2020-28332Barco wepresent wipg-1600w firmware download of code without integrity check vulnerabilityBarco wePresent WiPG-1600W devices download code without an Integrity Check. Affected Version(s): 2.5.1.8, 2.5.0.25, 2.5.0.24, 2.4.1.19. The Barco we…EPSS 1.1%9.8CVE-2020-28334Barco wepresent wipg-1600w firmware hard-coded credentials vulnerabilityBarco wePresent WiPG-1600W devices use Hard-coded Credentials (issue 2 of 2). Affected Version(s): 2.5.1.8, 2.5.0.25, 2.5.0.24, 2.4.1.19. The Barco w…EPSS 4.8%9.8CVE-2019-3930Crestron am-100 firmware stack-based buffer overflow vulnerabilityThe Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W befo…EPSS 7.0%7.5CVE-2020-28331Barco wepresent wipg-1600w firmware vulnerabilityBarco wePresent WiPG-1600W devices have Improper Access Control. Affected Version(s): 2.5.1.8. The Barco wePresent WiPG-1600W device has an SSH daemo…EPSS 1.7%6.5CVE-2020-28330Barco wepresent wipg-1600w firmware insufficiently protected credentials vulnerabilityBarco wePresent WiPG-1600W devices have Unprotected Transport of Credentials. Affected Version(s): 2.5.1.8. An attacker armed with hardcoded API cred…EPSS 1.2%5.9CVE-2025-68686FortiOS symbolic link patch bypass exposes sensitive informationFortiOS contains an information exposure flaw (CWE-200) that lets a remote unauthenticated attacker bypass the patch for the symbolic link persistenc…KEVEPSS 30%analysed

Source: NIST National Vulnerability Database (record CVE-2020-28333), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.