An improper access control vulnerability exists in Bitdefender Box 1 (firmware version 1.3.52.928 and below) that allows an unauthenticated attacker to downgrade the device's firmware to an older, potentially vulnerable version of a Bitdefender-signed firmware. The attack requires Bitdefender BOX to be booted in Recovery Mode and that the attacker be present within the WiFi range of the BOX unit.
Metrics
Affected Vendors & Products
References
History
Wed, 30 Jul 2025 01:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Bitdefender
Bitdefender box Bitdefender box Firmware |
|
CPEs | cpe:2.3:h:bitdefender:box:-:*:*:*:*:*:*:* cpe:2.3:o:bitdefender:box_firmware:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Bitdefender
Bitdefender box Bitdefender box Firmware |
|
Metrics |
cvssV3_1
|
Sat, 12 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Wed, 12 Mar 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 12 Mar 2025 12:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An improper access control vulnerability exists in Bitdefender Box 1 (firmware version 1.3.52.928 and below) that allows an unauthenticated attacker to downgrade the device's firmware to an older, potentially vulnerable version of a Bitdefender-signed firmware. The attack requires Bitdefender BOX to be booted in Recovery Mode and that the attacker be present within the WiFi range of the BOX unit. | |
Title | Unauthenticated Firmware Downgrade in Bitdefender Box v1 | |
Weaknesses | CWE-1328 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: Bitdefender
Published: 2025-03-12T11:48:35.528Z
Updated: 2025-03-12T14:01:55.166Z
Reserved: 2025-02-13T17:36:42.145Z
Link: CVE-2024-13870

Updated: 2025-03-12T14:01:49.878Z

Status : Analyzed
Published: 2025-03-12T12:15:12.443
Modified: 2025-07-30T00:52:04.430
Link: CVE-2024-13870

No data.