CVE-2019-13473
9.8
CRITICAL · CVSS 3.1 · EPSS 4% (pctl 90)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
TELESTAR Bobs Rock Radio, Dabman D10, Dabman i30 Stereo, Imperial i110, Imperial i150, Imperial i200, Imperial i200-cd, Imperial i400, Imperial i450, Imperial i500-bt, and Imperial i600 TN81HH96-g102h-g102 devices have an undocumented TELNET service within the BusyBox subsystem, leading to root access.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.98% — more likely to be exploited than 90% of all CVEs |
| Weakness | CWE-798 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2019-09-11 |
| Last modified | 2026-06-17 |
Affected (24)
| Vendor | Product |
|---|---|
| auna | connect 100 |
| auna | connect 100 firmware |
| telestar | bobs rock radio |
| telestar | bobs rock radio firmware |
| telestar | dabman d10 |
| telestar | dabman d10 firmware |
| telestar | dabman i30 stereo |
| telestar | dabman i30 stereo firmware |
| telestar | imperial i110 |
| telestar | imperial i110 firmware |
| telestar | imperial i150 |
| telestar | imperial i150 firmware |
| telestar | imperial i200 |
| telestar | imperial i200 firmware |
| telestar | imperial i200-cd |
| telestar | imperial i200-cd firmware |
| telestar | imperial i400 |
| telestar | imperial i400 firmware |
| telestar | imperial i450 |
| telestar | imperial i450 firmware |
| telestar | imperial i500-bt |
| telestar | imperial i500-bt firmware |
| telestar | imperial i600 |
| telestar | imperial i600 firmware |
References
- http://packetstormsecurity.com/files/154416/Dabman-And-Imperial-Web-Radio-Devices-Undocumented-Telnet-Backdoor.html
- http://packetstormsecurity.com/files/174503/Internet-Radio-auna-IR-160-SE-UIProto-DoS-XSS-Missing-Authentication.html
- http://seclists.org/fulldisclosure/2023/Sep/1
- https://www.vulnerability-lab.com/get_content.php?id=2183
- http://packetstormsecurity.com/files/154416/Dabman-And-Imperial-Web-Radio-Devices-Undocumented-Telnet-Backdoor.html
- http://packetstormsecurity.com/files/174503/Internet-Radio-auna-IR-160-SE-UIProto-DoS-XSS-Missing-Authentication.html
- http://seclists.org/fulldisclosure/2023/Sep/1
- https://www.vulnerability-lab.com/get_content.php?id=2183
→ the Explorer · watch your stack · NVD