CVE-2019-5014: Wincofireworks Fw-1007 Firmware

Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.

An exploitable improper access control vulnerability exists in the bluetooth low energy functionality of Winco Fireworks FireFly FW-1007 V2.0. An attacker can connect to the device to trigger this vulnerability.

Affected products

Published 2019-05-08. Last modified 2026-06-17.