Blynk develops a compact portfolio of IoT connectivity and remote-access libraries and server software, with a durable signal centered on memory-safety and path-handling weaknesses such as out-of-bounds reads and writes, stack-based buffer overflows, and path-traversal issues. Current vulnerability counts, severity distribution, and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Blynk over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-17785HIGH In blynk-server in Blynk before 0.39.7, Directory Traversal exists via a ../ in a URI that has /static or /static/js at the beginning, as demonstrated by reading the /etc/passwd fi | Sep 30, 2018 | 7.5 | 25 | NO | NO |
CVE-2022-29496CRITICAL A stack-based buffer overflow vulnerability exists in the BlynkConsole.h runCommand functionality of Blynk -Library v1.0.1. A specially-crafted network request can lead to command | Jun 17, 2022 | 9.8 | 24 | NO | NO |
CVE-2019-5065MEDIUM An exploitable information disclosure vulnerability exists in the packet-parsing functionality of Blynk-Library v0.6.1. A specially crafted packet can cause an unterminated strncpy | Sep 5, 2019 | 5.3 | 20 | NO | NO |
CVE-2014-7019MEDIUM The Clarks Inn (aka com.ClarksInn) application 3.3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and | Oct 16, 2014 | 5.4 | 15 | NO | NO |
CVE-2014-6969MEDIUM The Deltin Suites (aka com.DeltinSuites) application 3.4.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof server | Oct 16, 2014 | 5.4 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Blynk.
Media articles that mention a CVE ID that affects a product developed by Blynk — matched by CVE ID, not by vendor name.