CVE-2012-4249 describes a critical command injection vulnerability in the Amazon Lab126 com.lab126.system sendEvent implementation on Kindle Touch devices running firmware versions older than 5.1.2. This flaw allows unauthenticated attackers to execute arbitrary commands remotely by injecting shell metacharacters into string inputs, specifically when setting LIPC properties. With a CVSS score of 10.0, this vulnerability poses a severe risk, enabling complete compromise of confidentiality, integrity, and availability. Despite its critical severity, there is no public exploit intelligence available, nor any record of active exploitation or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.1.0CPE matchmatch criteria | cpe:2.3:h:amazon:kindle_touch:5.1.0:*:*:*:*:*:*:* | ||
5.1.1CPE matchmatch criteria | cpe:2.3:h:amazon:kindle_touch:5.1.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.