216.73.217.22

CVE-2025-5346

· Published 17/07/2025 13:15 · Modified 17/07/2025 21:15

Labels: CVE-2025-5346 2025-07-17CVE-2025-5346CWE-926[email protected]

Essential information

Published
17/07/2025 13:15
Modified
17/07/2025 21:15
Author
Creator
CVSS
5.1 MEDIUM (v3) 5.1 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Bluebird devices contain a pre-loaded barcode scanner application. This application exposes an unsecured broadcast receiver "kr.co.bluebird.android.bbsettings.BootReceiver". A local attacker can call the receiver to overwrite file containing ".json" keyword with default barcode config file. It is possible to overwrite file in any location due to lack of protection against path traversal in name of the file. This issue affects all versions before 1.3.3.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
bluebird / barcode scanner application cpe:2.3:a:bluebird:barcode_scanner_application:<1.3.3:*:*:*:*:*:*:*

References