U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Search Results (Refine Search)

Search Parameters:
  • Results Type: Overview
  • Keyword (text search): cpe:2.3:o:amazon:blink_xt2_sync_module_firmware:2.3.11:*:*:*:*:*:*:*
There are 6 matching records.
Displaying matches 1 through 6.
Vuln ID Summary CVSS Severity
CVE-2019-3989

Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when retrieving internal network configuration data.

Published: December 11, 2019; 6:15:11 PM -0500
V3.1: 9.8 CRITICAL
V2.0: 9.3 HIGH
CVE-2019-3988

Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the bssid parameter.

Published: December 11, 2019; 6:15:11 PM -0500
V3.1: 8.8 HIGH
V2.0: 8.3 HIGH
CVE-2019-3987

Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the key parameter.

Published: December 11, 2019; 6:15:11 PM -0500
V3.1: 8.8 HIGH
V2.0: 8.3 HIGH
CVE-2019-3986

Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the encryption parameter.

Published: December 11, 2019; 6:15:11 PM -0500
V3.1: 8.8 HIGH
V2.0: 8.3 HIGH
CVE-2019-3985

Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the ssid parameter.

Published: December 11, 2019; 6:15:11 PM -0500
V3.1: 8.8 HIGH
V2.0: 8.3 HIGH
CVE-2019-3983

Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary code and commands on the device due to insufficient UART protections.

Published: December 11, 2019; 6:15:11 PM -0500
V3.1: 6.8 MEDIUM
V2.0: 7.2 HIGH