First published: Wed Jul 01 2020(Updated: )
An issue was discovered on Zolo Halo devices via the Linkplay firmware. There is Zolo Halo LAN remote code execution. The Zolo Halo Bluetooth speaker had a GoAhead web server listening on the port 80. The /httpapi.asp endpoint of the GoAhead web server was also vulnerable to multiple command execution vulnerabilities.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linkplay |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-15311 has a severity rating of high due to its potential for remote code execution.
To fix CVE-2019-15311, ensure that your Zolo Halo device firmware is updated to the latest version provided by the manufacturer.
CVE-2019-15311 is classified as a remote code execution vulnerability affecting Zolo Halo devices.
CVE-2019-15311 specifically affects Zolo Halo Bluetooth speakers using Linkplay firmware.
An attacker can exploit CVE-2019-15311 to execute arbitrary commands on Zolo Halo devices via the vulnerable web server.