Executive brief
Pyxis Signage, a digital signage management platform, contains a security flaw that allows high-privileged users to upload dangerous file types. This could allow an attacker to bypass intended access controls and gain unauthorized access to system functions. If exploited, this could lead to a full compromise of the signage system, affecting the integrity of displayed content and overall service availability.
Technical details
An unrestricted upload of file with dangerous type (CWE-434) exists in Narkom Pyxis Signage through version 31012025. The vulnerability allows an attacker with high privileges (PR:H) to upload malicious files, which subsequently enables the bypassing of Access Control Lists (ACLs) to access restricted functionality. The attack is reachable over the network without user interaction. Successful exploitation grants the attacker full control over the confidentiality, integrity, and availability of the affected system.
Affected products
- Narkom Communication and Software Technologies Trade Ltd. Co. Pyxis Signage through 31012025
Timeline
- 2025-11-20: advisory: Initial disclosure by TR-CERT/USOM