CVE Feed

    Dashboard / CVE / CVE-2019-15310

    CVE-2019-15310

    An issue was discovered on various devices via the Linkplay firmware. There is WAN remote code execution without user interaction. An attacker could retrieve the AWS key from the firmware and obtain full control over Linkplay's AWS estate, including S3 buckets containing device firmware. When combined with an OS command injection vulnerability within the XML Parsing logic of the firmware update process, an attacker would be able to gain code execution on any device that attempted to update. Note that by default all devices tested had automatic updates enabled.

    Published:Jul 1, 2020
    Last Modified:Nov 21, 2024
    EPS:Jul 1, 2020
    EPSS Score:0.11928
    CVSS Score:9.8

    Affected Products

    Vendor
    Linkplay
    Product
    Linkplay

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High