CVE-2019-3950: Arlo VMB3010 Firmware

Critical severity, CVSS 9.8. EPSS: 1.8% chance of exploitation in the next 30 days.

Arlo Basestation firmware 1.12.0.1_27940 and prior contain a hardcoded username and password combination that allows root access to the device when an onboard serial interface is connected to.

Affected products

  • Arlo VMB3010 Firmware: before 1.12.2.3_2762 (fixed in 1.12.2.3_2762)
  • Arlo VMB3500 Firmware: before 1.12.2.4_2773 (fixed in 1.12.2.4_2773)
  • Arlo VMB4000 Firmware: before 1.12.2.3_2762 (fixed in 1.12.2.3_2762)
  • Arlo VMB4500 Firmware: before 1.12.2.4_2773 (fixed in 1.12.2.4_2773)
  • Arlo VMB5000 Firmware: before 1.12.2.2_2824 (fixed in 1.12.2.2_2824)

Published 2019-07-09. Last modified 2026-06-17.