CVE-2019-13143
Last modified
CVE-2019-13143 is a vulnerability of currently unknown severity. An HTTP parameter pollution issue was discovered on Shenzhen Dragon Brothers Fingerprint Bluetooth Round Padlock FB50 2.3. With the user ID, user name, and the lock's MAC address, anyone can unbind the existing owner of the lock, and bind themselves instead. EPSS estimates a 3.06% chance of exploitation in the next 30 days.
Description
An HTTP parameter pollution issue was discovered on Shenzhen Dragon Brothers Fingerprint Bluetooth Round Padlock FB50 2.3. With the user ID, user name, and the lock's MAC address, anyone can unbind the existing owner of the lock, and bind themselves instead. This leads to complete takeover of the lock. The user ID, name, and MAC address are trivially obtained from APIs found within the Android or iOS application. With only the MAC address of the lock, any attacker can transfer ownership of the lock from the current user, over to the attacker's account. Thus rendering the lock completely inaccessible to the current user.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Shenzhen Dragon Brothers | Fb50 Firmware | 2.3 |
References
- http://blog.securelayer7.net/fb50-smart-lock-vulnerability-disclosure/Exploit, Third Party Advisory
- http://blog.securelayer7.net/fb50-smart-lock-vulnerability-disclosure/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-13143?
How severe is CVE-2019-13143?
How do I fix CVE-2019-13143?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-13136ImageMagick before 7.0.8-50 has an integer overflow vulnerab…
- CVE-2019-13137ImageMagick before 7.0.8-50 has a memory leak vulnerability …6.5
- CVE-2019-13139In Docker before 18.09.4, an attacker who is capable of supp…
- CVE-2019-1314A security feature bypass vulnerability exists in Windows 10…6.8
- CVE-2019-13140Inteno EG200 EG200-WU7P1U_ADAMO3.16.4-190226_1650 routers ha…6.5
- CVE-2019-13142The RzSurroundVADStreamingService (RzSurroundVADStreamingSer…
- CVE-2019-13144myTinyTodo 1.3.3 through 1.4.3 allows CSV Injection. This is…9.8
- CVE-2019-13145Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-13146The field_test gem 0.3.0 for Ruby has unvalidated input. A m…
- CVE-2019-13147In Audio File Library (aka audiofile) 0.3.6, there exists on…6.5
- CVE-2019-13148An issue was discovered in TRENDnet TEW-827DRU firmware befo…
- CVE-2019-13149An issue was discovered in TRENDnet TEW-827DRU firmware befo…
Are you affected by CVE-2019-13143?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
