CVE-2019-3985: Amazon Blink XT2 Sync Module Firmware

High severity, CVSS 8.8. EPSS: 1.7% chance of exploitation in the next 30 days.

Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the ssid parameter.

Affected products

  • Amazon Blink XT2 Sync Module Firmware: before 2.13.11 (fixed in 2.13.11)

Published 2019-12-11. Last modified 2026-06-17.