CRITICAL🇵🇱 Wersja polska

CVE-2024-13871

CVSS 9.4v4.0pub. 2025-03-12upd. 2025-07-30

A command injection vulnerability exists in the /check_image_and_trigger_recovery API endpoint of Bitdefender Box 1 (firmware version 1.3.11.490). This flaw allows an unauthenticated, network-adjacent attacker to execute arbitrary commands on the device, potentially leading to full remote code execution (RCE).

🤖 AI Analysis
How it works

The vulnerability (CWE-77) consists of insufficient validation and sanitization of input data passed to the `/check_image_and_trigger_recovery` endpoint in the device API. An attacker located on the same local network can send a specially crafted request containing malicious system commands that will be executed directly by the device's operating system. The lack of authentication mechanisms on this endpoint eliminates any access barrier for the attacker.

Impact

An attacker can gain full control over the Bitdefender Box 1 device by executing arbitrary system commands (RCE), which may lead to breach of confidentiality, integrity, and availability of both the device itself and systems connected to it.

Mitigation & patch

Apply patches available from the manufacturer according to the references. Details are available in the official Bitdefender security advisory: https://bitdefender.com/support/security-advisories/unauthenticated-command-injection-in-bitdefender-box-v1. Until the update is applied, it is recommended to isolate the device from untrusted segments of the local network.

Who is affected

Bitdefender Box 1 with firmware version 1.3.11.490

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Bitdefender Box

    HW
    Bitdefender
    all versions
  • Bitdefender Box Firmware

    OS
    Bitdefender
    1.3.11.490
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2024-13872CRITICAL9.4PL ✓same product

Niezabezpieczony mechanizm aktualizacji w Bitdefender Box — RCE przez MITM

CVE-2019-12612HIGH7.8same product

An issue was discovered in Bitdefender BOX firmware versions before 2.1.37.37-34 that allows an attacker to pa...

CVE-2019-12611MEDIUM4.4same product

An issue was discovered in Bitdefender BOX firmware versions before 2.1.37.37-34 that affects the general reli...

CVE-2024-13870LOW1.8same product

W Bitdefender Box 1 (wersja oprogramowania 1.3.52.928 i starsze) istnieje podatność w kontroli dostępu, która ...

CVE-2025-1987CRITICAL9.3PL ✓same vendor

Stored XSS w Psono Client / Bitdefender SecurePass via złośliwe URL w magazynie haseł