CVE-2019-16732

Severity CVSS v4.0:
Pending analysis
Type:
CWE-319 Cleartext Transmission of Sensitive Information
Publication date:
13/12/2019
Last modified:
21/07/2021

Description

Unencrypted HTTP communications for firmware upgrades in Petalk AI and PF-103 allow man-in-the-middle attackers to run arbitrary code as the root user.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:skymee:petalk_ai_firmware:3.2.2.30:*:*:*:*:*:*:*
cpe:2.3:h:skymee:petalk_ai:-:*:*:*:*:*:*:*
cpe:2.3:o:petwant:pf-103_firmware:4.22.2.42:*:*:*:*:*:*:*
cpe:2.3:h:petwant:pf-103:-:*:*:*:*:*:*:*