Loading HuntDB...

GHSA-29h2-5h98-8vhx

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

Bluebird devices contain a pre-loaded barcode scanner application. This application exposes an unsecured broadcast receiver "kr.co.bluebird.android.bbsettings.BootReceiver". A local attacker can call the receiver to overwrite file containing ".json" keyword with default barcode config file. It is possible to overwrite file in any location due to lack of protection against path traversal in name of the file.

This issue affects all versions before 1.3.3.

Related CVEs

Key Information

GHSA ID
GHSA-29h2-5h98-8vhx
Published
July 17, 2025 3:32 PM
Last Modified
July 17, 2025 3:32 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 26, 2025 6:37 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.