Bluebird devices contain a pre-loaded barcode scanner application. This application exposes an unsecured broadcast receiver "kr.co.bluebird.android.bbsettings.BootReceiver". A local attacker can call the receiver to overwrite file containing ".json" keyword with default barcode config file. It is possible to overwrite file in any location due to lack of protection against path traversal in name of the file.
This issue affects all versions before 1.3.3.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://cert.pl/en/posts/2025/07CVE-2025-5344 |
![]() ![]() |
History
Thu, 17 Jul 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 17 Jul 2025 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Bluebird devices contain a pre-loaded barcode scanner application. This application exposes an unsecured broadcast receiver "kr.co.bluebird.android.bbsettings.BootReceiver". A local attacker can call the receiver to overwrite file containing ".json" keyword with default barcode config file. It is possible to overwrite file in any location due to lack of protection against path traversal in name of the file. This issue affects all versions before 1.3.3. | |
Title | File removal via path traversal in unsecured broadcast receiver in Bluebird barcode scanner application | |
Weaknesses | CWE-926 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: CERT-PL
Published: 2025-07-17T12:45:56.546Z
Updated: 2025-07-17T13:44:05.369Z
Reserved: 2025-05-30T06:40:16.684Z
Link: CVE-2025-5346

Updated: 2025-07-17T13:43:47.620Z

Status : Awaiting Analysis
Published: 2025-07-17T13:15:23.383
Modified: 2025-07-17T21:15:50.197
Link: CVE-2025-5346

No data.