CVE-2019-3949: Arlo VMB3010 Firmware

Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.

Arlo Basestation firmware 1.12.0.1_27940 and prior firmware contain a networking misconfiguration that allows access to restricted network interfaces. This could allow an attacker to upload or download arbitrary files and possibly execute malicious code on the device.

Affected products

  • Arlo VMB3010 Firmware: before 1.12.2.3_2762 (fixed in 1.12.2.3_2762)
  • Arlo VMB3500 Firmware: before 1.12.2.4_2773 (fixed in 1.12.2.4_2773)
  • Arlo VMB4000 Firmware: before 1.12.2.3_2762 (fixed in 1.12.2.3_2762)
  • Arlo VMB4500 Firmware: before 1.12.2.4_2773 (fixed in 1.12.2.4_2773)
  • Arlo VMB5000 Firmware: before 1.12.2.2_2824 (fixed in 1.12.2.2_2824)

Published 2019-07-09. Last modified 2026-06-17.