Bluebird devices contain a pre-loaded barcode scanner application. This application exposes an unsecured broadcast receiver "kr.co.bluebird.android.bbsettings.BootReceiver". A local attacker can call the receiver to overwrite file containing ".json" keyword with default barcode config file. It is possible to overwrite file in any location due to lack of protection against path traversal in name of the file.
This issue affects all versions before 1.3.3.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://cert.pl/en/posts/2025/07CVE-2025-5344 |
|
History
Thu, 17 Jul 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 17 Jul 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Bluebird devices contain a pre-loaded barcode scanner application. This application exposes an unsecured broadcast receiver "kr.co.bluebird.android.bbsettings.BootReceiver". A local attacker can call the receiver to overwrite file containing ".json" keyword with default barcode config file. It is possible to overwrite file in any location due to lack of protection against path traversal in name of the file. This issue affects all versions before 1.3.3. | |
| Title | File removal via path traversal in unsecured broadcast receiver in Bluebird barcode scanner application | |
| Weaknesses | CWE-926 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published: 2025-07-17T12:45:56.546Z
Updated: 2025-07-17T13:44:05.369Z
Reserved: 2025-05-30T06:40:16.684Z
Link: CVE-2025-5346
Updated: 2025-07-17T13:43:47.620Z
Status : Awaiting Analysis
Published: 2025-07-17T13:15:23.383
Modified: 2025-07-17T21:15:50.197
Link: CVE-2025-5346
No data.