CVE-2019-16110: Blade-Group Shadow

High severity, CVSS 8.1. EPSS: 1.7% chance of exploitation in the next 30 days.

The network protocol of Blade Shadow though 2.13.3 allows remote attackers to take control of a Shadow instance and execute arbitrary code by only knowing the victim's IP address, because packet data can be injected into the unencrypted UDP packet stream.

Affected products

Published 2019-11-14. Last modified 2026-06-17.