CVE-2019-3985: OS Command Injection
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the ssid parameter.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for the Blink XT2 Sync Module firmware vulnerability?
The vulnerability ID for the Blink XT2 Sync Module firmware vulnerability is CVE-2019-3985.
What is the severity of CVE-2019-3985?
CVE-2019-3985 has a severity rating of 8.8 (High).
How does CVE-2019-3985 allow remote attackers to execute arbitrary commands?
CVE-2019-3985 allows remote attackers to execute arbitrary commands on the Blink XT2 Sync Module firmware due to improperly sanitized input when configuring the devices wifi configuration via the ssid parameter.
What is the affected software for CVE-2019-3985?
The affected software for CVE-2019-3985 is the Blink XT2 Sync Module firmware prior to version 2.13.11.
How can I fix CVE-2019-3985 vulnerability?
To fix the CVE-2019-3985 vulnerability, it is recommended to update the Blink XT2 Sync Module firmware to version 2.13.11 or later.