PT-2025-11033 · Bitdefender · Bitdefender Box

Alan Cao

·

Published

2025-03-12

·

Updated

2025-07-30

·

CVE-2024-13872

CVSS v4.0

9.4

Critical

VectorAV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions: Bitdefender Box versions 1.3.11.490 through 1.3.11.505
Description: The issue concerns the use of the insecure HTTP protocol to download assets over the Internet for updating and restarting daemons and detection rules on devices. Updates can be remotely triggered through the "/set temp token" API endpoint. This allows an unauthenticated and network-adjacent attacker to use man-in-the-middle (MITM) techniques to return malicious responses. As a result, restarted daemons that use malicious assets can be exploited for remote code execution on the device.
Recommendations: For Bitdefender Box versions 1.3.11.490 through 1.3.11.505, consider disabling the /set temp token API method until a secure update mechanism is implemented to prevent remote code execution risks. Restrict access to the device to minimize the risk of exploitation. Avoid using the insecure HTTP protocol for updates until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-03184
CVE-2024-13872

Affected Products

Bitdefender Box