CVE-2024-13871 Information
Mar 13, 2025
cve
Description
A command injection vulnerability exists in the /check_image_and_trigger_recovery API endpoint of Bitdefender Box 1 (firmware version 1.3.11.490). This flaw allows an unauthenticated network-adjacent attacker to execute arbitrary commands on the device potentially leading to full remote code execution (RCE).