Bluebird devices contain a pre-loaded barcode scanner application. This application exposes an unsecured broadcast receiver "kr.co.bluebird.android.bbsettings.BootReceiver". A local attacker can call the receiver to overwrite file containing ".json" keyword with default barcode config file. It is possible to overwrite file in any location due to lack of protection against path traversal in name of the file. This issue affects all versions before 1.3.3.
History

Thu, 17 Jul 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Jul 2025 13:15:00 +0000

Type Values Removed Values Added
Description Bluebird devices contain a pre-loaded barcode scanner application. This application exposes an unsecured broadcast receiver "kr.co.bluebird.android.bbsettings.BootReceiver". A local attacker can call the receiver to overwrite file containing ".json" keyword with default barcode config file. It is possible to overwrite file in any location due to lack of protection against path traversal in name of the file. This issue affects all versions before 1.3.3.
Title File removal via path traversal in unsecured broadcast receiver in Bluebird barcode scanner application
Weaknesses CWE-926
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published: 2025-07-17T12:45:56.546Z

Updated: 2025-07-17T13:44:05.369Z

Reserved: 2025-05-30T06:40:16.684Z

Link: CVE-2025-5346

cve-icon Vulnrichment

Updated: 2025-07-17T13:43:47.620Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-17T13:15:23.383

Modified: 2025-07-17T21:15:50.197

Link: CVE-2025-5346

cve-icon Redhat

No data.