Home

Description

ReQuest Serious Play F3 Media Server versions 7.0.3.4968 (Pro), 7.0.2.4954, 6.5.2.4954, 6.4.2.4681, 6.3.2.4203, and 2.0.1.823 contain a remote denial-of-service vulnerability. The device can be shut down or rebooted by an unauthenticated attacker through a single crafted HTTP GET request, allowing remote interruption of service availability.

PUBLISHED Reserved 2025-11-14 | Published 2025-11-14 | Updated 2025-11-18 | Assigner VulnCheck




HIGH: 8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Problem types

CWE-400 Uncontrolled Resource Consumption

Product status

Default status
unknown

7.0.3.4968
affected

Default status
unknown

7.0.2.4954
affected

6.5.2.4954
affected

6.4.2.4681
affected

6.3.2.4203
affected

2.0.1.823
affected

Timeline

2020-10-18:ZSL-2020-5601 is publicly disclosed.

Credits

Gjoko Krstic of Zero Science Lab finder

References

www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5601.php exploit

www.exploit-db.com/exploits/48951 exploit

cxsecurity.com/issue/WLB-2020100122 exploit

www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5601.php technical-description exploit

www.exploit-db.com/exploits/48951 exploit

packetstorm.news/files/id/159602 exploit

cxsecurity.com/issue/WLB-2020100122 exploit

exchange.xforce.ibmcloud.com/vulnerabilities/190031 vdb-entry

www.request.com/ product

www.vulncheck.com/...serious-play-f3-media-server-remote-dos third-party-advisory

cve.org (CVE-2021-4465)

nvd.nist.gov (CVE-2021-4465)

Download JSON