Bitdefender Box 1
cpe:2.3:h:bitdefender:box:*:*:*:*:*:*:*, +1 more
- <= 1.3.52.928
A vulnerability allowing improper access control has been identified in Bitdefender Box 1, specifically in firmware versions through 1.3.52.928. This vulnerability enables an unauthenticated attacker to downgrade the device's firmware to an older, potentially vulnerable version that is still signed by Bitdefender. The exploitation of this vulnerability requires the Bitdefender Box to be in Recovery Mode and for the attacker to be within WiFi range of the device.
Exploitation of this vulnerability allows for an unauthorized firmware downgrade, potentially introducing known vulnerabilities from the downgraded firmware version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.