TrendMakers Sight Bulb Pro Command Injection Vulnerability Allowing Root Shell Access
Vulnerability
A command injection vulnerability has been identified in the TrendMakers Sight Bulb Pro, specifically in versions through 8.57.83. This vulnerability allows unauthenticated users on an adjacent network to execute arbitrary shell commands as root. The issue arises through a proprietary TCP protocol on Port 16668, where a well-formed JSON string can be used to inject commands.
Impact
Exploitation of this vulnerability could lead to unauthorized execution of shell commands as root on the affected device.
Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
5.0exploitability
4.9remediation
0.0relevance
0.2threat
0.0urgency
2.9incentive
0.8Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
