CVE-2019-5014: Wincofireworks Fw-1007 Firmware
Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.
An exploitable improper access control vulnerability exists in the bluetooth low energy functionality of Winco Fireworks FireFly FW-1007 V2.0. An attacker can connect to the device to trigger this vulnerability.
Affected products
- Wincofireworks Fw-1007 Firmware: version 2.0 only
Published 2019-05-08. Last modified 2026-06-17.