CVE-2019-3989: Amazon Blink XT2 Sync Module Firmware

Critical severity, CVSS 9.8. EPSS: 3.7% chance of exploitation in the next 30 days.

Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when retrieving internal network configuration data.

Affected products

  • Amazon Blink XT2 Sync Module Firmware: before 2.13.11 (fixed in 2.13.11)

Published 2019-12-11. Last modified 2026-06-17.