Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-13870

18
FAUCET Score

CVE-2024-13870 is an improper access control vulnerability affecting Bitdefender Box 1 devices running firmware version 1.3.52.928 and below. An unauthenticated attacker within Wi-Fi range can force the device into Recovery Mode and downgrade its firmware to an older, potentially vulnerable Bitdefender-signed version. This medium-severity vulnerability (CVSS 5.7) requires physical proximity and user interaction for exploitation, leading to high integrity impact but no confidentiality or availability impact. There is currently no public exploit code, active exploitation, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
<= 1.3.52.928CPE matchmatch criteria
cpe:2.3:o:bitdefender:box_firmware:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

1.8LOW

CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:X/RE:X/U:X

Attack Vector
LOCAL
Attack Complexity
HIGH
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
ACTIVE
VS Confidentiality
LOW
VS Integrity
LOW
VS Availability
NONE
SS Confidentiality
LOW
SS Integrity
LOW
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.16%
Probability of exploitation in next 30 days
EPSS Percentile
5.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0016 is in the 13th percentile among its peer group of 126 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (5)

elasticvendor investigatingvia llm_extracted
hyperledgervendor investigatingvia llm_extracted
View patch
jenkinsvendor investigatingvia llm_extracted
View patch
libvipsvendor investigatingvia llm_extracted
power_bivendor investigatingvia llm_extracted
View patch

Vendor Advisories (5)

power_billm-power_bi-7da7409fb2b1b4b0

Unauthenticated Firmware Downgrade in Bitdefender Box v1

Mar 12, 2025
libvipsllm-libvips-2d0b1146fe5ca792

Unauthenticated Firmware Downgrade in Bitdefender Box v1

Mar 12, 2025
hyperledgerllm-hyperledger-ad25d63b782f8dd4

Unauthenticated Firmware Downgrade in Bitdefender Box v1

Mar 12, 2025
jenkinsllm-jenkins-46e9383792eadd3b

Unauthenticated Firmware Downgrade in Bitdefender Box v1

Mar 12, 2025
elasticllm-elastic-7cf845a9d9177979

Unauthenticated Firmware Downgrade in Bitdefender Box v1

Mar 12, 2025

References

bitdefender.com / support/security-advisories/unauthenticated-firmware-downgrade-in-bitdefender-box-v1
Vendor Advisory