CVE-2019-11561
Description
The Chuango 433 MHz burglar-alarm product line is vulnerable to a Denial of Service attack. When the condition is triggered, the OV2 base station is unable to process sensor states and effectively prevents the alarm from setting off, as demonstrated by Chuango branded products, and non-Chuango branded products such as the Eminent EM8617 OV2 Wifi Alarm System.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Chuango 433 MHz burglar-alarm base stations are vulnerable to a denial-of-service attack that prevents the alarm from triggering.
Vulnerability
The Chuango 433 MHz burglar-alarm product line, including the OV2 base station and many Chuango-branded and OEM products such as the Eminent EM8617 OV2 Wifi Alarm System, contains a vulnerability in the handling of 433 MHz RF interface requests. An attacker can cause a denial-of-service (DoS) condition by sending malicious RF signals that overwhelm the base station, making it unable to process sensor states. All versions of the affected product lines are considered vulnerable, as per the vendor disclosure timeline [1].
Exploitation
An attacker needs only physical proximity to transmit a specially crafted 433 MHz RF signal to the base station. No authentication or special privileges are required. The attacker sends a continuous or high-volume series of RF requests, which the base station processes, causing a DoS condition. Once the condition is triggered, the base station becomes unresponsive to legitimate sensor triggers, such as door/window contacts or motion detectors [1].
Impact
Successful exploitation results in the base station being unable to process sensor states, effectively disabling the alarm system. The alarm will not set off when an intrusion occurs, as the base station ignores sensor inputs. The confidentiality and integrity of the system are not directly compromised, but availability is severely impacted, allowing physical intrusions to go undetected [1].
Mitigation
As of the disclosure timeline (April 2019), the vendor was notified but did not respond. No official fix, patch, or workaround has been published for the affected products. Users of the Chuango product line and OEM rebrands (e.g., Eminent EM8617) should consider replacing the device or implementing physical countermeasures, such as shielding or disabling RF reception, until a fix becomes available. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog as of this writing [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- Chuango/433 MHz burglar-alarm product linedescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/RiieCco/write-ups/tree/master/CVE-2019-11561mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.