CVE-2019-17096

CRITICAL

Bitdefender BOX 2 Firmware - OS Command Injection via get_image_url() Function

Title source: llm
STIX 2.1

Description

A OS Command Injection vulnerability in the bootstrap stage of Bitdefender BOX 2 allows the manipulation of the `get_image_url()` function in special circumstances to inject a system command.

Scores

CVSS v3 9.0
EPSS 0.0207
EPSS Percentile 79.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (3)
bitdefender/box_2_firmware
bitdefender/central < 2.0.66
bitdefender/central < 2.0.66.88
Published Jan 27, 2020
Tracked Since Feb 18, 2026