CVE-2023-28704

Furbo dog camera has insufficient filtering for special parameter of device log management function. An unauthenticated remote attacker in the Bluetooth network with normal user privileges can exploit this vulnerability to perform command injection attack to execute arbitrary system commands or disrupt service.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:furbo:dog_camera_firmware:542:*:*:*:*:*:*:*
cpe:2.3:h:furbo:dog_camera:-:*:*:*:*:*:*:*

History

21 Nov 2024, 07:55

Type Values Removed Values Added
References () https://www.twcert.org.tw/tw/cp-132-7153-68f52-1.html - Third Party Advisory () https://www.twcert.org.tw/tw/cp-132-7153-68f52-1.html - Third Party Advisory

14 Oct 2024, 04:15

Type Values Removed Values Added
CWE CWE-77 CWE-78

09 Jun 2023, 18:22

Type Values Removed Values Added
First Time Furbo dog Camera
Furbo dog Camera Firmware
Furbo
References (MISC) https://www.twcert.org.tw/tw/cp-132-7153-68f52-1.html - (MISC) https://www.twcert.org.tw/tw/cp-132-7153-68f52-1.html - Third Party Advisory
CPE cpe:2.3:o:furbo:dog_camera_firmware:542:*:*:*:*:*:*:*
cpe:2.3:h:furbo:dog_camera:-:*:*:*:*:*:*:*

02 Jun 2023, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-06-02 11:15

Updated : 2024-11-21 07:55


NVD link : CVE-2023-28704

Mitre link : CVE-2023-28704

CVE.ORG link : CVE-2023-28704


JSON object : View

Products Affected

furbo

  • dog_camera
  • dog_camera_firmware
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')