Bluebird Devices Barcode Scanner Application BootReceiver Overwrite Vulnerability

Vulnerability

A vulnerability exists in Bluebird devices with a pre-loaded barcode scanner application, prior to version 1.3.3. The issue arises from an unsecured broadcast receiver, 'kr.co.bluebird.android.bbsettings.BootReceiver', which allows local attackers to overwrite any file containing the '.json' keyword. This is achieved by replacing it with a default barcode configuration file. The vulnerability is exacerbated by a lack of protection against path traversal, enabling file overwrites in any location.

Impact

Exploitation of this vulnerability allows for arbitrary file overwriting, potentially leading to disruption of application functionality or user data.

Added: Jul 17, 2025, 1:16 PM
Updated: Jul 17, 2025, 1:16 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
3.3
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.