Sceawere

Vulnerability Detail

CVE-2026-100902UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Barco ClickShare Wallpaper DoS

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
4h ago
Vendor
Barco
Product
ClickShare CX-20 Gen2
Attack Type
Denial of Service
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was determined in Barco ClickShare CX-20 Gen2 up to 02.26.00.0007. Affected by this issue is some unknown functionality of the file /wallpaper of the component Wallpaper Upload. This manipulation of the argument wallpaper causes denial of service. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-09-28T04:16:56.207Z",
  "pubdate": "2026-09-28T04:16:56.207Z",
  "executiveSummary": "A denial of service vulnerability exists within the Barco ClickShare CX-20 Gen2 firmware up to version 02.26.00.0007. The vulnerability resides in the Wallpaper Upload component, specifically affecting the /wallpaper endpoint. By manipulating the wallpaper argument, a remote, unauthenticated attacker can cause the device to enter a state of denial of service. This vulnerability poses a significant risk to operational continuity, as the affected ClickShare device becomes unresponsive and unable to perform its primary function of wireless conferencing and presentation. Given that the exploit has been publicly disclosed and the vendor has remained unresponsive to disclosure attempts, the risk of exploitation is elevated. Organizations utilizing these devices should implement immediate network-level restrictions to prevent unauthorized access to the affected interface.",
  "technicalDetails": "The vulnerability is situated within the Wallpaper Upload component of the Barco ClickShare CX-20 Gen2, which provides functionality for users to customize the device's standby screen. The root cause of the denial of service appears to be improper input validation or insufficient error handling within the /wallpaper endpoint when processing the wallpaper argument. Because the interface is exposed remotely, an attacker can transmit a specially crafted request containing malicious or malformed data to the endpoint.\nThe attack flow involves the attacker sending an HTTP request directed at the /wallpaper file, targeting the specific parameter intended for file handling or configuration. Upon receiving the crafted payload, the underlying service or application logic, which manages the processing of the uploaded image or configuration file, encounters an unhandled exception or enters an infinite loop. This failure results in the crash of the associated system process or the exhaustion of system resources, causing the device to stop responding to legitimate user traffic or control signals.\nThe affected versions include Barco ClickShare CX-20 Gen2 firmware up to 02.26.00.0007. The vulnerability is exploitable remotely, requiring no prior authentication or administrative privileges, which increases the potential attack surface. The payload behavior is destructive to service availability, effectively forcing a device hang or reboot cycle that prevents normal operation. As the functionality involves file uploads or configuration updates, the system likely fails when attempting to parse or write the manipulated argument to the filesystem or memory buffer, leading to process termination. The impact is a complete disruption of the conferencing session functionality, necessitating a hard reset or power cycle to restore the device to its normal operating state. Since the exploit is publicly available, any device with network connectivity to the management interface is at risk."
}
CVE-2026-100902: Barco ClickShare Wallpaper DoS (MEDIUM Severity, CVSS: 6.5) | Sceawere