ZeroHour

CVE-2019-3984

PoC
CVSS 3.1
9.8 critical
EPSS
4%p89
Published
()
Modified
Description

Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when the device retrieves updates scripts from the internet.

Vendors
amazon
Products
blink xt2 sync module firmware
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.