CVE-2019-15312: Linkplay

High severity, CVSS 8.8. EPSS: 2.9% chance of exploitation in the next 30 days.

An issue was discovered on Zolo Halo devices via the Linkplay firmware. There is a Zolo Halo DNS rebinding attack. The device was found to be vulnerable to DNS rebinding. Combined with one of the many /httpapi.asp endpoint command-execution security issues, the DNS rebinding attack could allow an attacker to compromise the victim device from the Internet.

Affected products

  • Linkplay Linkplay: affected versions not specified

Published 2020-07-01. Last modified 2026-06-17.