CVE-2019-17096: Bitdefender Box 2 Firmware

Critical severity, CVSS 9.8. EPSS: 2.1% chance of exploitation in the next 30 days.

A OS Command Injection vulnerability in the bootstrap stage of Bitdefender BOX 2 allows the manipulation of the `get_image_url()` function in special circumstances to inject a system command.

Affected products

  • Bitdefender Box 2 Firmware: affected versions not specified
  • Bitdefender Central: before 2.0.66 (fixed in 2.0.66); before 2.0.66.88 (fixed in 2.0.66.88)

Published 2020-01-27. Last modified 2026-06-17.