Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-13870


An improper access control vulnerability exists in Bitdefender Box 1 (firmware version 1.3.52.928 and below) that allows an unauthenticated attacker to downgrade the device's firmware to an older, potentially vulnerable version of a Bitdefender-signed firmware. The attack requires Bitdefender BOX to be booted in Recovery Mode and that the attacker be present within the WiFi range of the BOX unit.


Published

2025-03-12T12:15:12.443

Last Modified

2025-07-30T00:52:04.430

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.7 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-1328

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System bitdefender box_firmware ≤ 1.3.52.928 Yes
Hardware bitdefender box - No

References