Bose SoundTouch devices allows remote attackers to achieve remote control via a crafted web site that uses the WebSocket Protocol.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HBose Soundtouch
APPBoseall versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2018-12638MEDIUM6.1same product
An issue was discovered in the Bose Soundtouch app 18.1.4 for iOS. There is no frontend input validation of th...
CVE-2017-17749MEDIUM5.4same product
Bose SoundTouch devices allow XSS via crafted song data from a music service, as demonstrated by Pandora.
CVE-2017-17750MEDIUM5.4same product
Bose SoundTouch devices allow XSS via a crafted public playlist from Spotify.
CVE-2017-6520CRITICAL9.1PL ✓same vendor
Bose Soundtouch 30: błąd mDNS umożliwia DoS i ujawnienie informacji