Skip to main content

Vendor/product archive

bitdefender / box_firmware CVEs

Beta · best-effort

5 CVEs tagged to bitdefender / box_firmware2 Critical, 1 High, 1 Medium, 1 Low, 0 Unrated.

CVE-2024-13872

Published Mar 12, 2025

Bitdefender Box, versions 1.3.11.490 through 1.3.11.505, uses the insecure HTTP protocol to download assets over the Internet to update and restart daemons and detection rules on…

CVSS 9.4 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-13871

Published Mar 12, 2025

A command injection vulnerability exists in the /check_image_and_trigger_recovery API endpoint of Bitdefender Box 1 (firmware version 1.3.11.490). This flaw allows an unauthentica…

CVSS 9.4 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-12612

Published Oct 31, 2019

An issue was discovered in Bitdefender BOX firmware versions before 2.1.37.37-34 that allows an attacker to pass arbitrary code to the BOX appliance via the web API. In order to e…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-12611

Published Oct 17, 2019

An issue was discovered in Bitdefender BOX firmware versions before 2.1.37.37-34 that affects the general reliability of the product. Specially crafted packets sent to the miniupn…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1