A command injection vulnerability has been discovered in the bootstrap stage of Bitdefender BOX 2, versions 2.1.47.42 and 2.1.53.45. The API method `/api/download_image` unsafely handles the production firmware URL supplied by remote servers, leading to arbitrary execution of system commands. In order to exploit the condition, an unauthenticated attacker should impersonate a infrastructure server to trigger this vulnerability.
Conclusion & alert: CVE-2019-17095 is rated High Exploit Risk (73.4/100): CVSS High severity, with medium exploitation likelihood (EPSS 4.41%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-11-21 | 10.16% | 4.41% | -5.75% |
| 2 | 2025-11-18 | 4.41% | 10.16% | +5.75% |
| 3 | 2025-05-04 | — | 4.41% | — |
Full EPSS history (19 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.1 | 3.1 | HIGH |
|
1.4 | 6.0 | [email protected] |
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
| 10.0 | 2.0 | HIGH |
|
10.0 | 10.0 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| bitdefender | box_2_firmware | 2.1.47.42 | cpe:2.3:o:bitdefender:box_2_firmware:2.1.47.42:*:*:*:*:*:*:* |
| bitdefender | box_2_firmware | 2.1.53.45 | cpe:2.3:o:bitdefender:box_2_firmware:2.1.53.45:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://www.bitdefender.com/support/security-advisories/command-injection-vulnerability-in-bitdefender-box-v2-va-5706 | Broken Link |
| https://talosintelligence.com/vulnerability_reports/TALOS-2019-0919 | Exploit Third Party Advisory |
| https://www.cybersecurity-help.cz/vdb/SB2020012215?affChecked=1 | Third Party Advisory |