CVE-2019-3988
8.8
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the bssid parameter.
Affected (1)
Products: Amazon: Blink Xt2 Sync Module Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.13.11 |
| Running on/with | Platform Versions |
|---|---|
Amazon Blink Xt2 Sync Module | All versions |
References (2)
Source: vulnreport@tenable.com
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Timeline
No history available yet.