{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-02T23:30:38.632","vulnerabilities":[{"cve":{"id":"CVE-2024-40893","sourceIdentifier":"disclosure@vulncheck.com","published":"2024-08-12T19:15:16.643","lastModified":"2026-06-17T07:46:48.457","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Multiple authenticated operating system (OS) command injection vulnerabilities exist in Firewalla Box Software \nversions before 1.979. A physically close \nattacker that is authenticated to the Bluetooth Low-Energy (BTLE) interface can use the network configuration service to inject commands in various configuration parameters including networkConfig.Interface.Phy.Eth0.Extra.PingTestIP, networkConfig.Interface.Phy.Eth0.Extra.DNSTestDomain, and networkConfig.Interface.Phy.Eth0.Gateway6. Additionally, because the configuration can be synced to the Firewalla cloud, the attacker may be able to persist access even after hardware resets and firmware re-flashes."},{"lang":"es","value":"Existen múltiples vulnerabilidades de inyección de comandos del sistema operativo (SO) autenticado en las versiones del software Firewalla Box anteriores a la 1.979. Un atacante físicamente cercano que esté autenticado en la interfaz Bluetooth Low-Energy (BTLE) puede usar el servicio de configuración de red para inyectar comandos en varios parámetros de configuración, incluidos networkConfig.Interface.Phy.Eth0.Extra.PingTestIP, networkConfig.Interface.Phy.Eth0.Extra.DNSTestDomain y networkConfig.Interface.Phy.Eth0.Gateway6. Además, debido a que la configuración se puede sincronizar con la nube de Firewalla, el atacante puede persistir en el acceso incluso después de reiniciar el hardware y actualizar el firmware."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"Firewalla","product":"Box Software","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"1.979","versionType":"custom","status":"affected"}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"firewalla","product":"box_software","defaultStatus":"unknown","cpes":["cpe:2.3:a:firewalla:box_software:*:*:*:*:*:*:*:*"],"versions":[{"version":"0","lessThan":"1.979","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":6.8,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":0.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-08-14T13:25:43.056042Z","id":"CVE-2024-40893","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-78"}]}],"references":[{"url":"https://vulncheck.com/advisories/firewalla-bt-command-injection","source":"disclosure@vulncheck.com"},{"url":"https://www.labs.greynoise.io/grimoire/2024-08-20-bluuid-firewalla/","source":"disclosure@vulncheck.com"}]}}]}