Vulnerability Description
TELESTAR Bobs Rock Radio, Dabman D10, Dabman i30 Stereo, Imperial i110, Imperial i150, Imperial i200, Imperial i200-cd, Imperial i400, Imperial i450, Imperial i500-bt, and Imperial i600 TN81HH96-g102h-g102 devices have insufficient access control for the /set_dname, /mylogo, /LocalPlay, /irdevice.xml, /Sendkey, /setvol, /hotkeylist, /init, /playlogo.jpg, /stop, /exit, /back, and /playinfo commands.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Telestar | Bobs Rock Radio Firmware | - |
| Telestar | Bobs Rock Radio | - |
| Telestar | Dabman D10 Firmware | - |
| Telestar | Dabman D10 | - |
| Telestar | Dabman I30 Stereo Firmware | - |
| Telestar | Dabman I30 Stereo | - |
| Telestar | Imperial I110 Firmware | - |
| Telestar | Imperial I110 | - |
| Telestar | Imperial I150 Firmware | - |
| Telestar | Imperial I150 | - |
| Telestar | Imperial I200 Firmware | - |
| Telestar | Imperial I200 | - |
| Telestar | Imperial I200-Cd Firmware | - |
| Telestar | Imperial I200-Cd | - |
| Telestar | Imperial I400 Firmware | - |
| Telestar | Imperial I400 | - |
| Telestar | Imperial I450 Firmware | - |
| Telestar | Imperial I450 | - |
| Telestar | Imperial I500-Bt Firmware | - |
| Telestar | Imperial I500-Bt | - |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/174503/Internet-Radio-auna-IR-160-SE-UIProt
- http://seclists.org/fulldisclosure/2019/Sep/12Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2023/Sep/1
- https://www.vulnerability-lab.com/get_content.php?id=2183ExploitThird Party Advisory
- http://packetstormsecurity.com/files/174503/Internet-Radio-auna-IR-160-SE-UIProt
- http://seclists.org/fulldisclosure/2019/Sep/12Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2023/Sep/1
- https://www.vulnerability-lab.com/get_content.php?id=2183ExploitThird Party Advisory
FAQ
What is CVE-2019-13474?
CVE-2019-13474 is a vulnerability with a CVSS score of 9.8 (CRITICAL). TELESTAR Bobs Rock Radio, Dabman D10, Dabman i30 Stereo, Imperial i110, Imperial i150, Imperial i200, Imperial i200-cd, Imperial i400, Imperial i450, Imperial i500-bt, and Imperial i600 TN81HH96-g102h...
How severe is CVE-2019-13474?
CVE-2019-13474 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-13474?
Check the references section above for vendor advisories and patch information. Affected products include: Telestar Bobs Rock Radio Firmware, Telestar Bobs Rock Radio, Telestar Dabman D10 Firmware, Telestar Dabman D10, Telestar Dabman I30 Stereo Firmware.