CVE-2019-13336: Dbell DB01-S Firmware

Critical severity, CVSS 9.8. EPSS: 2.9% chance of exploitation in the next 30 days.

The dbell Wi-Fi Smart Video Doorbell DB01-S Gen 1 allows remote attackers to launch commands with no authentication verification via TCP port 81, because the loginuse and loginpass parameters to openlock.cgi can have arbitrary values. NOTE: the vendor's position is that this product reached end of life in 2016.

Affected products

  • Dbell DB01-S Firmware: affected versions not specified

Published 2019-10-08. Last modified 2026-06-17.