ReQuest Serious Play F3 Media Server versions 7.0.3.4968 (Pro), 7.0.2.4954, 6.5.2.4954, 6.4.2.4681, 6.3.2.4203, and 2.0.1.823 allows unauthenticated attackers to disclose the webserver's Python debug log file containing system information, credentials, paths, processes and command arguments running on the device. Attackers can access sensitive information by visiting the message_log page.
CVSS v4.0 Metrics
Exploitability
Attack VectorNetwork
ComplexityLow
RequirementsNone
PrivilegesNone
User InteractionNone
Threat
Exploit MaturityUnreported
Vulnerable System
ConfidentialityHigh
IntegrityNone
AvailabilityNone
Subsequent System
ConfidentialityNone
IntegrityNone
AvailabilityNone
Supplemental
SafetyNegligible
AutomatableYes
RecoveryAutomatic
Value DensityConcentrated
UrgencyMedium
Change Log
| Date | Source | Changes | Score |
|---|
| 2026-07-21 | cve.org | initial, patch: Unavailable | 6.6 |
Affected Software
| Vendor | Product | Version |
|---|
| ReQuest Serious Play LLC | ReQuest Serious Play | 2.0.1.823 |
| ReQuest Serious Play LLC | ReQuest Serious Play | 6.3.2.4203 |
| ReQuest Serious Play LLC | ReQuest Serious Play | 6.4.2.4681 |
| ReQuest Serious Play LLC | ReQuest Serious Play | 6.5.2.4954 |
| ReQuest Serious Play LLC | ReQuest Serious Play | 7.0.2.4954 |
| ReQuest Serious Play LLC | ReQuest Serious Play Pro | 7.0.3.4968 |
Published: 2025-12-05