CVE 5.1 MEDIUM

File removal via path traversal in unsecured broadcast receiver in Bluebird barcode scanner application_CVE-2025-5346

5.1 / 10
MEDIUM
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N

Description

Bluebird devices contain a pre-loaded barcode scanner application. This application exposes an unsecured broadcast receiver "kr.co.bluebird.android.bbsettings.BootReceiver". A local attacker can call the receiver to overwrite file containing ".json" keyword with default barcode config file. It is possible to overwrite file in any location due to lack of protection against path traversal in name of the file.

This issue affects all versions before 1.3.3.

Basic Information

ID CVE-2025-5346
Source CERT-PL
Published Jul 17, 2025 at 12:45
Modified Jul 17, 2025 at 13:44

Affected Product

Vendor Bluebird
Product kr.co.bluebird.android.bbsettings
Affected Versions Bluebird kr.co.bluebird.android.bbsettings 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.