CVE-2019-3984
Status: ModifiedCritical (9.8)—
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when the device retrieves updates scripts from the internet.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Base score: 9.8
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 3.77%
- Percentile among all scored CVEs: 90
- Score date: 10/6/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-78
References
Raw JSON (NVD)
Show
{
"id": "CVE-2019-3984",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 10,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "vulnreport@tenable.com",
"affectedData": [
{
"vendor": "Amazon",
"product": "Blink XT2 Sync Module firmware",
"versions": [
{
"status": "affected",
"version": "prior to 2.13.11"
}
]
}
]
}
],
"published": "2019-12-31T18:15:11.610",
"references": [
{
"url": "https://www.tenable.com/security/research/tra-2019-51",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "vulnreport@tenable.com"
},
{
"url": "https://www.tenable.com/security/research/tra-2019-51",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-78"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when the device retrieves updates scripts from the internet."
},
{
"lang": "es",
"value": "El módulo de sincronización Blink XT2 versiones del firmware anteriores a la versión 2.13.11, permite a atacantes remotos ejecutar comandos arbitrarios en el dispositivo debido a una entrada saneada inapropiadamente cuando el dispositivo recupera los scripts de actualizaciones de Internet."
}
],
"lastModified": "2026-06-17T02:35:59.833",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:amazon:blink_xt2_sync_module_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D760A965-7A5F-45DA-A530-3E8979A04F57",
"versionEndExcluding": "2.3.11"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:amazon:blink_xt2_sync_module:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "5AFBC607-8887-4CC7-99D0-60D9C8993EE9"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "vulnreport@tenable.com"
}