CVE-2019-13336
The dbell Wi-Fi Smart Video Doorbell DB01-S Gen 1 allows remote attackers to launch commands with no authentication verification via TCP port 81, because the loginuse and loginpass parameters to openlock.cgi can have arbitrary values.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.86%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The dbell Wi-Fi Smart Video Doorbell DB01-S Gen 1 allows remote attackers to launch commands with no authentication verification via TCP port 81, because the loginuse and loginpass parameters to openlock.cgi can have arbitrary values. NOTE: the vendor's position is that this product reached end of life in 2016.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.86% probability · 86th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- dbell/db01-s firmware
- Source
- cve@mitre.org
References
- http://noahclements.com/Improper-Input-Validation-on-dbell-Smart-Doorbell-Can-Lead-To-Attackers-Remotely-Unlocking-Door/Exploit, Third Party Advisory
- https://www.reddit.com/r/AskNetsec/comments/c9p22m/company_threatening_to_sue_me_if_i_publicly/Issue Tracking, Third Party Advisory
- https://www.youtube.com/watch?v=SkTKt1nV57IThird Party Advisory
- http://noahclements.com/Improper-Input-Validation-on-dbell-Smart-Doorbell-Can-Lead-To-Attackers-Remotely-Unlocking-Door/Exploit, Third Party Advisory
- https://www.reddit.com/r/AskNetsec/comments/c9p22m/company_threatening_to_sue_me_if_i_publicly/Issue Tracking, Third Party Advisory
- https://www.youtube.com/watch?v=SkTKt1nV57IThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.