CVE-2019-3949
Description
Arlo Basestation firmware 1.12.0.1_27940 and prior firmware contain a networking misconfiguration that allows access to restricted network interfaces. This could allow an attacker to upload or download arbitrary files and possibly execute malicious code on the device.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A networking misconfiguration in Arlo Base Station firmware up to 1.12.0.1_27940 allows LAN-based attackers to access the internal camera network interface and execute arbitrary code.
Vulnerability
Networking misconfiguration in Arlo Base Station firmware versions 1.12.0.1_27940 and prior allows an attacker on the same LAN to access the internal camera network interface [1]. Affected products include VMB3010, VMB4000, VMB3500, VMB4500, and VMB5000 [1]. The base station exposes two interfaces: one for the internal camera network and one for the external LAN; the misconfiguration permits traversal from the LAN to the camera network [1].
Exploitation
An attacker needs to be connected to the same local area network (LAN) as the Arlo Base Station [1]. No authentication or user interaction is required beyond network access [1]. The attacker can then communicate with the internal camera network interface, enabling upload or download of arbitrary files and potentially executing malicious code [1].
Impact
Successful exploitation allows an attacker to control the user’s Arlo cameras, upload or download arbitrary files, and potentially execute malicious code on the device [1]. This compromises the confidentiality, integrity, and availability of the camera system and associated data [1].
Mitigation
Arlo resolved this vulnerability through automatic firmware updates: VMB3010 and VMB4000 updated to 1.12.2.3_2762; VMB3500 and VMB4500 updated to 1.12.2.4_2773; VMB5000 updated to 1.12.2.2_2824 [1]. No workarounds are documented; users should ensure their devices have received the updates automatically [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <=1.12.0.1_27940
- Arlo/Basestation firmwarev5Range: 1.12.0.1_27940 and prior
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.