CVE-2019-3950: Arlo VMB3010 Firmware
Critical severity, CVSS 9.8. EPSS: 1.8% chance of exploitation in the next 30 days.
Arlo Basestation firmware 1.12.0.1_27940 and prior contain a hardcoded username and password combination that allows root access to the device when an onboard serial interface is connected to.
Affected products
- Arlo VMB3010 Firmware: before 1.12.2.3_2762 (fixed in 1.12.2.3_2762)
- Arlo VMB3500 Firmware: before 1.12.2.4_2773 (fixed in 1.12.2.4_2773)
- Arlo VMB4000 Firmware: before 1.12.2.3_2762 (fixed in 1.12.2.3_2762)
- Arlo VMB4500 Firmware: before 1.12.2.4_2773 (fixed in 1.12.2.4_2773)
- Arlo VMB5000 Firmware: before 1.12.2.2_2824 (fixed in 1.12.2.2_2824)
Published 2019-07-09. Last modified 2026-06-17.