CVE-2025-54756 Details
Description
BrightSign players running BrightSign OS series 4 prior to v8.5.53.1 or series 5 prior to v9.0.166 use a default password that is guessable with knowledge of the device information. The latest release fixes this issue for new installations; users of old installations are encouraged to change all default passwords.
A vulnerability exists in BrightSign players running BrightSign OS series 4 prior to v8.5.53.1 and series 5 prior to v9.0.166. These versions use a default password that can be easily guessed with knowledge of the device information. This vulnerability could lead to privilege escalation on the device, allow default passwords to be exploited, or enable arbitrary code execution on the underlying operating system.
Users are encouraged to change all default passwords. BrightSign has released patches for this vulnerability in v8.5.53.1 for series 4 players and v9.0.166 for series 5 players. Both versions are available on the BrightSign download site.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 12, 2026CISA-ADP
Assessed Feb 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2025/icsa-25-126-03.json | [email protected] | AdvisoryBundleRemedy |
| https://www.brightsign.biz/resources/software-downloads/ | [email protected] | ProductVendor |
| https://www.cisa.gov/news-events/ics-advisories/icsa-25-126-03 | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1392 | Use of Default Credentials | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| BrightSign OS | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 12, 2026 | New CVE Received | [email protected] |
Volerion