Junglewise Threat Intelligence

CVE-2020-37228: Guangzhou Yeroo iDS6 DSSPro CAPTCHA bypass in login interface

CVE-2020-37228 · Severity: critical · CVSS 9.8 · Published 2026-05-16

Executive brief

The iDS6 DSSPro Digital Signage System, used for managing networked digital displays, contains a flaw in its login security. An attacker can bypass the CAPTCHA verification intended to prevent automated attacks by simply requesting the code directly from the server. This allows unauthorized individuals to perform unlimited automated password-guessing attempts, potentially leading to full account takeover and control over the digital signage network.

Technical details

A CAPTCHA security bypass vulnerability exists in the authentication routine of the iDS6 DSSPro Digital Signage System. The application exposes the 'autoLoginVerifyCode' object via a specific endpoint (/Pages/login!autoLoginVerifyCode), which returns the valid CAPTCHA solution in a JSON response. A remote, unauthenticated attacker can programmatically retrieve this code and submit it alongside login credentials to the 'userValidate' endpoint. This effectively neutralizes the CAPTCHA protection, enabling high-speed brute-force or dictionary attacks against user accounts. The vulnerability affects multiple versions including 6.2, 5.6, and 4.3.

Affected products

  • Guangzhou Yeroo Tech Co., Ltd. iDS6 DSSPro Digital Signage System 6.2 B2014.12.12.1220, 5.6 B2017.07.12.1757, 4.3

Timeline

  • 2020-07-16: disclosed: Vulnerability discovered by Zero Science Lab
  • 2020-11-05: other: Exploit published on Exploit-DB
  • 2026-05-16: advisory: NVD/VulnCheck advisory published

References