iDS6 DSSPro Digital Signage System CAPTCHA Security Bypass Vulnerability

Vulnerability

A CAPTCHA bypass vulnerability has been identified in iDS6 DSSPro Digital Signage System version 6.2. This vulnerability allows attackers to circumvent authentication by requesting the autoLoginVerifyCode object. Exploiting this flaw, attackers can retrieve valid CAPTCHA codes through the login endpoint and use them to launch brute-force attacks against user accounts.

Impact

Exploitation of this vulnerability allows for authentication bypass, enabling attackers to perform brute-force attacks on user accounts.

Reproduction

To reproduce this vulnerability, first request the autoLoginVerifyCode object from the login endpoint. This will return a valid CAPTCHA code. Next, use this CAPTCHA code to bypass the authentication challenge by sending a request to the userValidate endpoint, including the CAPTCHA code and user credentials. This will successfully authenticate the user and bypass the CAPTCHA verification.

Added: May 16, 2026, 4:38 PM
Updated: May 16, 2026, 4:38 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
5.0
exploitability
9.1
remediation
0.0
relevance
8.1
threat
6.4
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.