Critical severity9.0NVD Advisory· Published Jan 27, 2020· Updated Jun 17, 2026
CVE-2019-17096
CVE-2019-17096
Description
A OS Command Injection vulnerability in the bootstrap stage of Bitdefender BOX 2 allows the manipulation of the get_image_url() function in special circumstances to inject a system command.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:bitdefender:central:*:*:*:*:*:android:*:*+ 1 more
- cpe:2.3:a:bitdefender:central:*:*:*:*:*:android:*:*range: <2.0.66.88
- cpe:2.3:a:bitdefender:central:*:*:*:*:*:iphone_os:*:*range: <2.0.66
- cpe:2.3:o:bitdefender:box_2_firmware:-:*:*:*:*:*:*:*
(expand)+ 1 more
- (no CPE)
- (no CPE)range: 2.1.47.42
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.