CVE-2019-3950 describes a critical vulnerability in Arlo Basestation firmware versions 1.12.0.1_27940 and earlier, affecting models such as the VMB3010, VMB4000, and VMB5000. The flaw involves a hardcoded username and password that grants root access when an attacker connects to the device's onboard serial interface. This vulnerability carries a CVSS score of 9.8 (Critical) due to its network-accessible attack vector, low complexity, and complete compromise of confidentiality, integrity, and availability. While no public exploits or active exploitation have been observed, and community discussion is minimal, the inherent risk remains high due to the ease of gaining full control over affected devices.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.12.2.3_2762CPE matchmatch criteria | cpe:2.3:o:arlo:vmb3010_firmware:*:*:*:*:*:*:*:* | ||
< 1.12.2.3_2762CPE matchmatch criteria | cpe:2.3:o:arlo:vmb4000_firmware:*:*:*:*:*:*:*:* | ||
< 1.12.2.4_2773CPE matchmatch criteria | cpe:2.3:o:arlo:vmb3500_firmware:*:*:*:*:*:*:*:* | ||
< 1.12.2.4_2773CPE matchmatch criteria | cpe:2.3:o:arlo:vmb4500_firmware:*:*:*:*:*:*:*:* | ||
< 1.12.2.2_2824CPE matchmatch criteria | cpe:2.3:o:arlo:vmb5000_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Arlo Basestation Firmware Multiple Vulnerabilities
Jul 1, 2019Arlo Basestation Firmware Multiple Vulnerabilities
Jul 1, 2019Arlo Basestation Firmware Multiple Vulnerabilities
Jul 1, 2019Arlo Basestation Firmware Multiple Vulnerabilities
Jul 1, 2019Arlo Basestation Firmware Multiple Vulnerabilities
Jul 1, 2019Arlo Basestation Firmware Multiple Vulnerabilities
Jul 1, 2019