HIGH🇵🇱 Wersja polska

CVE-2019-17095

CVSS 8.1v3.1pub. 2020-01-27upd. 2024-11-21

A command injection vulnerability has been discovered in the bootstrap stage of Bitdefender BOX 2, versions 2.1.47.42 and 2.1.53.45. The API method `/api/download_image` unsafely handles the production firmware URL supplied by remote servers, leading to arbitrary execution of system commands. In order to exploit the condition, an unauthenticated attacker should impersonate a infrastructure server to trigger this vulnerability.

CVSS Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Bitdefender Box 2

    HW
    Bitdefender
    all versions
  • Bitdefender Box 2 Firmware

    OS
    Bitdefender
    2.1.47.422.1.53.45
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth BypassCommand Injection
CWE
References

Related vulnerabilities

CVE-2019-17096CRITICAL9.0PL ✓same product

Command Injection w fazie bootstrap Bitdefender Box 2

CVE-2019-17102HIGH8.3same product

An exploitable command execution vulnerability exists in the recovery partition of Bitdefender BOX 2, version ...

CVE-2025-1987CRITICAL9.3PL ✓same vendor

Stored XSS w Psono Client / Bitdefender SecurePass via złośliwe URL w magazynie haseł

CVE-2025-2244CRITICAL9.5PL ✓same vendor

Niebezpieczna deserializacja PHP w Bitdefender GravityZone Console (RCE)

CVE-2024-13872CRITICAL9.4PL ✓same vendor

Niezabezpieczony mechanizm aktualizacji w Bitdefender Box — RCE przez MITM