CVE-2020-11921: Lush 2
High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.
An issue was discovered in Lush 2 through 2020-02-25. Due to the lack of Bluetooth traffic encryption, it is possible to hijack an ongoing Bluetooth connection between the Lush 2 and a mobile phone. This allows an attacker to gain full control over the device.
Affected products
- Lush 2 Lush 2: up to and including 2020-02-25
Published 2024-11-07. Last modified 2026-06-17.