Low severity3.7NVD Advisory· Published Aug 10, 2021· Updated Jul 5, 2026
CVE-2021-38365
CVE-2021-38365
Description
Winner (aka ToneWinner) desktop speakers through 2021-08-09 allow remote attackers to recover speech signals from the power-indicator LED via a telescope and an electro-optical sensor, aka a "Glowworm" attack.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- cpe:2.3:o:tonewinner:winner_desktop_speakers_firmware:*:*:*:*:*:*:*:*Range: <=2021-08-09
- Winner/desktop speakersdescription
- Range: <=2021-08-09
- Range: <=2021-08-09
Patches
Vulnerability mechanics
References
2- www.nassiben.com/glowworm-attacknvdExploitThird Party Advisory
- www.tonewinner.comnvdVendor Advisory
News mentions
0No linked articles in our index yet.