CVE-2019-3986
Summary
| CVE | CVE-2019-3986 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-12-11 23:15:00 UTC |
| Updated | 2019-12-13 20:54:00 UTC |
| Description | Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the encryption parameter. |
Risk And Classification
Problem Types: CWE-78
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Amazon | Blink Xt2 Sync Module | - | All | All | All |
| Hardware | Amazon | Blink Xt2 Sync Module | - | All | All | All |
| Operating System | Amazon | Blink Xt2 Sync Module Firmware | All | All | All | All |
| Operating System | Amazon | Blink Xt2 Sync Module Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Blink XT2 Sync Module Multiple Vulnerabilities - Research Advisory | Tenable® | CONFIRM | www.tenable.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.