Bitdefender Box 1
- 1.3.11.490
A command injection vulnerability has been identified in the Bitdefender Box 1, specifically in firmware version 1.3.11.490. The vulnerability resides in the '/check_image_and_trigger_recovery' API endpoint, where an unauthenticated, network-adjacent attacker can execute arbitrary commands on the device. This exploitation could potentially lead to full remote code execution.
Exploitation of this vulnerability allows for arbitrary command execution on the affected device, with the potential for full remote code execution.
Users can update to Bitdefender Box firmware version 1.3.11.510 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.