series 5 prior to v9.0.166 use a default password that is guessable with
knowledge of the device information. The latest release fixes this
issue for new installations; users of old installations are encouraged
to change all default passwords.
Metrics
Affected Vendors & Products
No advisories yet.
Solution
BrightSign fixed CVE-2025-54756 in v8.5.53.1 (for series 4 players) and v9.0.166 (for series 5 players). Both of these have been released and are available on the BrightSign download site. https://www.brightsign.biz/contact-us/
Workaround
BrightSign recommends the following security practices: * Change default passwords when the device is initially set up. * Disable the local DWS as described in "High Security settings". * Disable the SSH/telnet server when not being used - it is not enabled by default. * Devices should be located where an attacker does not have physical access to the device. * SD and USB ports can be disabled if not needed. For more information, please contact BrightSign via their website. https://www.brightsign.biz/contact-us/
Thu, 12 Feb 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 12 Feb 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | BrightSign players running BrightSign OS series 4 prior to v8.5.53.1 or series 5 prior to v9.0.166 use a default password that is guessable with knowledge of the device information. The latest release fixes this issue for new installations; users of old installations are encouraged to change all default passwords. | |
| Title | BrightSign Players Use of Default Credentials | |
| Weaknesses | CWE-1392 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-02-12T18:45:20.986Z
Reserved: 2025-07-30T19:03:10.145Z
Link: CVE-2025-54756
Updated: 2026-02-12T18:45:11.796Z
Status : Awaiting Analysis
Published: 2026-02-12T17:16:04.793
Modified: 2026-02-13T14:23:48.007
Link: CVE-2025-54756
No data.
OpenCVE Enrichment
No data.