Linkplay's vulnerability footprint centers on audio and smart-speaker products, with the durable signal concentrated on embedded-device risk patterns including OS command injection, authorization bypass via user-controlled keys, and hard-coded credentials. Treat this as a narrow vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Linkplay over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-15311CRITICAL An issue was discovered on Zolo Halo devices via the Linkplay firmware. There is Zolo Halo LAN remote code execution. The Zolo Halo Bluetooth speaker had a GoAhead web server liste | Jul 1, 2020 | 9.8 | 34 | NO | NO |
CVE-2019-15310CRITICAL An issue was discovered on various devices via the Linkplay firmware. There is WAN remote code execution without user interaction. An attacker could retrieve the AWS key from the f | Jul 1, 2020 | 9.8 | 34 | NO | NO |
CVE-2022-28605CRITICAL Hardcoded admin token in SoundBar apps in Linkplay SDK 1.00 allows remote attackers to gain admin privilege access in linkplay antifactory | Jun 2, 2022 | 9.8 | 31 | NO | NO |
CVE-2019-15312HIGH An issue was discovered on Zolo Halo devices via the Linkplay firmware. There is a Zolo Halo DNS rebinding attack. The device was found to be vulnerable to DNS rebinding. Combined | Jul 1, 2020 | 8.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Linkplay.
Media articles that mention a CVE ID that affects a product developed by Linkplay — matched by CVE ID, not by vendor name.