A command injection vulnerability exists in the /check_image_and_trigger_recovery API endpoint of Bitdefender Box 1 (firmware version 1.3.11.490). This flaw allows an unauthenticated, network-adjacent attacker to execute arbitrary commands on the device, potentially leading to full remote code execution (RCE).
CVE ID: CVE-2024-13871
CVSS Base Severity: CRITICAL
CVSS Base Score: 9.4
CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Vendor: Bitdefender
Product: BOX v1
EPSS Score: 0.26% (probability of being exploited)
EPSS Percentile: 46.24% (scored less or equal to compared to others)
EPSS Date: 2025-04-10 (when was this score calculated)