CVE-2018-20161: Medium severity amazon blink xt2 sync module vulnerability
A design flaw in the BlinkForHome (aka Blink For Home) Sync Module 2.10.4 and earlier allows attackers to disable cameras via Wi-Fi, because incident clips (triggered by the motion sensor) are not saved if the attacker's traffic (such as Dot11Deauth) successfully disconnects the Sync Module from the Wi-Fi network. (Access to live video from the app also becomes unavailable.)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-20161?
CVE-2018-20161 is classified as a medium severity vulnerability due to its potential impact on camera functionality.
How do I fix CVE-2018-20161?
To fix CVE-2018-20161, upgrade the Blink Sync Module to version 2.10.5 or later.
What does CVE-2018-20161 allow attackers to do?
CVE-2018-20161 allows attackers to disable cameras by disconnecting the Sync Module via Wi-Fi.
Which devices are affected by CVE-2018-20161?
CVE-2018-20161 affects the Blink For Home Sync Module versions 2.10.4 and earlier.
What type of attack is associated with CVE-2018-20161?
CVE-2018-20161 is associated with a Wi-Fi deauthentication attack, specifically Dot11Deauth.