CVE-2019-11561
Estado: ModificadaMedia (5.9)—
The Chuango 433 MHz burglar-alarm product line is vulnerable to a Denial of Service attack. When the condition is triggered, the OV2 base station is unable to process sensor states and effectively prevents the alarm from setting off, as demonstrated by Chuango branded products, and non-Chuango branded products such as the Eminent EM8617 OV2 Wifi Alarm System.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 5.9
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.03%
- Percentil entre todas las CVEs puntuadas: 63
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (10)
CWE
- NVD-CWE-noinfo
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2019-11561",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:N/A:P",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 5.9,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 2.2
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2019-05-08T16:29:00.407",
"references": [
{
"url": "https://github.com/RiieCco/write-ups/tree/master/CVE-2019-11561",
"tags": [
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://github.com/RiieCco/write-ups/tree/master/CVE-2019-11561",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Chuango 433 MHz burglar-alarm product line is vulnerable to a Denial of Service attack. When the condition is triggered, the OV2 base station is unable to process sensor states and effectively prevents the alarm from setting off, as demonstrated by Chuango branded products, and non-Chuango branded products such as the Eminent EM8617 OV2 Wifi Alarm System."
},
{
"lang": "es",
"value": "La línea de productos de Chuango 433 MHz burglar-alarm es vulnerable a un ataque de Denegación de Servicio (DoS). Cuando se desencadena la condición, la estación base OV2 no puede procesar los estados del sensor y evita efectivamente que la alarma se active, como lo demuestran los productos de la marca Chuango y los productos que no son de la marca Chuango, como el Sistema de Alarma Wifi Eminent EM8617 OV2."
}
],
"lastModified": "2026-06-17T02:13:10.553",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:chuango:h4_plus_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8EE2554B-9133-4F7C-8554-3F87326F8344"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:chuango:h4_plus:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "E262EA5C-3892-477A-8631-F2FAA41A68E5"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:chuango:awv_plus_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "384FE3F0-F25D-4A9F-B0A8-E09749EAFE94"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:chuango:awv_plus:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "2DF78053-0866-46E0-A2D2-EA3703CFD17E"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:chuango:g5w_3g_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EEC30326-2456-4512-976C-85FF50063209"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:chuango:g5w_3g:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "4DFB1915-79B1-4C4B-99F0-E3842513D490"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:chuango:g5_plus_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C8433794-76AA-488E-973C-8BD4EEC69EF9"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:chuango:g5_plus:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "5EBF99D1-925B-477F-A902-8AAE69F30EDB"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:chuango:g3_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C56F8CEF-58AE-4B44-A7B6-9214C4241C76"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:chuango:g3:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "12B797E1-6192-4723-98E4-4C52638CCB8F"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:chuango:g5w_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D262A07A-A567-449B-8F32-4FB23547E9DD"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:chuango:g5w:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "1C862397-76E0-443F-8D7E-65D79FB68B93"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:chuango:b11_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "43093E4A-71D7-43DB-81EC-6F1F63EAD5A9"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:chuango:b11:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "08EC493D-9086-4D05-A01A-F2859271C1E1"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:chuango:a8_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D6E3AB30-511A-4CA6-8E4E-C4496937EEF1"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:chuango:a8:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "4FB7F927-C0F4-457A-A606-2250422703BE"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:chuango:a11_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C33EBDD4-DCA7-43E4-81FB-BE70A071B995"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:chuango:a11:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "B26BC888-FBD1-4506-8E50-32D0DA5966A4"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:chuango:cg-105s_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "86133042-400D-43CC-A960-B4A92AB4C50F"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:chuango:cg-105s:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "DD0E4AC9-0721-4010-A2AF-B7850E2F7F48"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cve@mitre.org"
}