VYPR

BOX 2

by Bitdefender

CVEs (1)

  • CVE-2019-17095HigJan 27, 2020
    risk 0.53cvss 8.1epss 0.04

    A command injection vulnerability has been discovered in the bootstrap stage of Bitdefender BOX 2, versions 2.1.47.42 and 2.1.53.45. The API method `/api/download_image` unsafely handles the production firmware URL supplied by remote servers, leading to arbitrary execution of…