CRITICAL

CVE-2019-15310

CVSS v3

9.8

CRITICAL

EPSS Score

11.9%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

An issue was discovered on various devices via the Linkplay firmware. There is WAN remote code execution without user interaction. An attacker could retrieve the AWS key from the firmware and obtain full control over Linkplay's AWS estate, including S3 buckets containing device firmware. When combined with an OS command injection vulnerability within the XML Parsing logic of the firmware update process, an attacker would be able to gain code execution on any device that attempted to update. Note that by default all devices tested had automatic updates enabled.

Technical details

Published
7/1/2020

Frequently asked questions

What is CVE-2019-15310?

An issue was discovered on various devices via the Linkplay firmware. There is WAN remote code execution without user interaction. An attacker could retrieve the AWS key from the firmware and obtain full control over Linkplay's AWS estate, including S3 buckets containing device firmware. When combined with an OS command injection vulnerability within the XML Parsing logic of the firmware update process, an attacker would be able to gain code execution on any device that attempted to update. Note that by default all devices tested had automatic updates enabled.

Is CVE-2019-15310 actively exploited?

Active exploitation of CVE-2019-15310 has not been confirmed. The EPSS score is 11.9%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2019-15310?

CVE-2019-15310 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2019-15310 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.