ReQuest Serious Play F3 Media Server Debug Log Disclosure Vulnerability

Vulnerability

A vulnerability in ReQuest Serious Play F3 Media Server has been identified, allowing unauthenticated attackers to access the webserver's Python debug log file. This log file contains sensitive system information, including credentials, file paths, processes, and command arguments related to the device's operation. The vulnerability affects versions 7.0.3.4968 (Pro), 7.0.2.4954, 6.5.2.4954, 6.4.2.4681, 6.3.2.4203, and 2.0.1.823. Attackers can exploit this issue by visiting the message_log page on the server.

Impact

Exploitation of this vulnerability leads to unauthorized disclosure of sensitive information, including system details, user credentials, and command execution logs.

Reproduction

To reproduce this vulnerability, access the message_log page on a server running an affected version of ReQuest Serious Play F3 Media Server. The Python debug log will be disclosed, containing sensitive information such as system processes, paths, and credentials.

Added: Dec 5, 2025, 6:42 PM
Updated: Dec 5, 2025, 6:42 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.7
remediation
0.0
relevance
1.3
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.