TrendMakers Sight Bulb Pro Command Injection Vulnerability Allowing Root Shell Access

Vulnerability

A command injection vulnerability has been identified in the TrendMakers Sight Bulb Pro, specifically in versions through 8.57.83. This vulnerability allows unauthenticated users on an adjacent network to execute arbitrary shell commands as root. The issue arises through a proprietary TCP protocol on Port 16668, where a well-formed JSON string can be used to inject commands.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of shell commands as root on the affected device.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
4.9
remediation
0.0
relevance
0.2
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.