Vulnerability Watch

Forum Discussion

snarang's avatar
snarang
Product Team
6 years ago

Tenable Research Advisory: Multiple Vulnerabilities in Arlo...

Tenable Research Advisory: Multiple Vulnerabilities in Arlo Base Station Firmware

On July 1, Tenable Research published a research advisory for vulnerabilities discovered in the firmware for Netgear’s Arlo camera base station. They include an insufficient UART protection mechanism vulnerability, and a networking configuration vulnerability. We also discovered a hardcoded private key in the firmware that was decrypted. We have assigned two CVE identifiers for these discoveries, which are CVE-2019-3949 and CVE-2019-3950. Arlo also published a security advisory as a knowledge base entry.

Our research team published a detailed analysis on the Tenable Techblog on how we discovered these vulnerabilities.

To learn more, please visit the Tenable Techblog post about this advisory.

1 Reply

  • frolla's avatar
    frolla
    Connect Contributor II

    Good. will certainly have a look at that.