VendorsBitdefenderboxall versions
Vulnerabilities

Bitdefender BOX

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2024-13871
Unauthenticated Command Injection in Bitdefender BOX v1
Published 2025-03-12 · Analyzed
9.4EPSS 0.008
CVE-2024-13872
Bitdefender Box Insecure Update Mechanism Vulnerability in libboxhermes.so
Published 2025-03-12 · Analyzed
9.4EPSS 0.002
CVE-2019-12612
An issue was discovered in Bitdefender BOX firmware versions before 2.1.37.37-34 that allows an attacker to pass arbitrary code to the BOX appliance via the web API. In order to exploit this vulnerability, an attacker needs presence in Bitdefender BOX setup network and Bitdefender BOX be in setup mode.
Published 2019-10-31 · Modified
7.8EPSS 0.003
CVE-2024-13870
Unauthenticated Firmware Downgrade in Bitdefender Box v1
Published 2025-03-12 · Analyzed
5.7EPSS 0.002
CVE-2019-12611
An issue was discovered in Bitdefender BOX firmware versions before 2.1.37.37-34 that affects the general reliability of the product. Specially crafted packets sent to the miniupnpd implementation in result in the device allocating memory without freeing it later. This behavior can cause the miniupnpd component to crash or to trigger a device reboot.
Published 2019-10-17 · Modified
4.9EPSS 0.003