peter bassill · operator
$ cve CVE-2019-13143 JSON

CVE-2019-13143

9.8
CRITICAL · CVSS 3.0 · EPSS 3.1% (pctl 87)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

An HTTP parameter pollution issue was discovered on Shenzhen Dragon Brothers Fingerprint Bluetooth Round Padlock FB50 2.3. With the user ID, user name, and the lock's MAC address, anyone can unbind the existing owner of the lock, and bind themselves instead. This leads to complete takeover of the lock. The user ID, name, and MAC address are trivially obtained from APIs found within the Android or iOS application. With only the MAC address of the lock, any attacker can transfer ownership of the lock from the current user, over to the attacker's account. Thus rendering the lock completely inaccessible to the current user.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.06% — more likely to be exploited than 87% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploitnone known
Published2019-08-06
Last modified2026-06-17

Affected (2)

VendorProduct
shenzhen dragon brothersfb50
shenzhen dragon brothersfb50 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD