CVE-2019-3984: Amazon Blink XT2 Sync Module Firmware
Critical severity, CVSS 9.8. EPSS: 3.8% chance of exploitation in the next 30 days.
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when the device retrieves updates scripts from the internet.
Affected products
- Amazon Blink XT2 Sync Module Firmware: before 2.3.11 (fixed in 2.3.11)
Published 2019-12-31. Last modified 2026-06-17.