CVE-2019-3984

CRITICAL WAF: High
CVSS 9.8 Published: 2019-12-31
CWE-78

Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when the device retrieves updates scripts from the internet.

WAF Coverage Analysis

OS Command Injection High WAF Coverage

OWASP: A03:2021 Injection

932xxx - Remote Code Execution

Affected Software

VendorProductVersion
amazonblink_xt2_sync_module_firmwareup to 2.3.11

References

Back to CVE Database