PT-2025-11031 · Bitdefender · Bitdefender Box

·

CVE-2024-13870

·

Published

2025-03-12

·

Updated

2025-07-30

CVSS v3.1

5.7

Medium

VectorAV:A/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: Bitdefender Box 1 versions 1.3.52.928 and below
Description: An improper access control issue exists that allows an unauthenticated attacker to downgrade the device's firmware to an older, potentially vulnerable version of a Bitdefender-signed firmware. The attack requires the device to be booted in Recovery Mode and the attacker to be within the WiFi range of the unit.
Recommendations: For Bitdefender Box 1 versions 1.3.52.928 and below, update the firmware to a version above 1.3.52.928 to prevent potential downgrades to vulnerable firmware versions. As a temporary workaround, consider restricting access to the Recovery Mode to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-13870

Affected Products

Bitdefender Box