CVE-2023-28704

Furbo dog camera has insufficient filtering for special parameter of device log management function. An unauthenticated remote attacker in the Bluetooth network with normal user privileges can exploit this vulnerability to perform command injection attack to execute arbitrary system commands or disrupt service.
References
Link Resource
https://www.twcert.org.tw/tw/cp-132-7153-68f52-1.html Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:h:furbo:dog_camera:-:*:*:*:*:*:*:*
cpe:2.3:o:furbo:dog_camera_firmware:542:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-06-02 11:15

Updated : 2023-06-09 18:22


NVD link : CVE-2023-28704

Mitre link : CVE-2023-28704

CVE.ORG link : CVE-2023-28704


JSON object : View

Products Affected

furbo

  • dog_camera_firmware
  • dog_camera
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')