PT-2020-9686 · Zolo Halo+1 · Zolo Halo+1
Published
2020-07-01
·
Updated
2021-07-21
·
CVE-2019-15312
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Zolo Halo devices via the Linkplay firmware (affected versions not specified)
Description
An issue was discovered that allows a DNS rebinding attack on the device. This attack, combined with command-execution security issues via the "/httpapi.asp" endpoint, could allow an attacker to compromise the victim device from the Internet.
Recommendations
As a temporary workaround, consider restricting access to the "/httpapi.asp" endpoint until a patch is available.
Avoid using the device until a fix is provided, to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linkplay
Zolo Halo