This issue affects all versions before 1.3.3.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-21762 | Bluebird devices contain a pre-loaded barcode scanner application. This application exposes an unsecured broadcast receiver "kr.co.bluebird.android.bbsettings.BootReceiver". A local attacker can call the receiver to overwrite file containing ".json" keyword with default barcode config file. It is possible to overwrite file in any location due to lack of protection against path traversal in name of the file. This issue affects all versions before 1.3.3. |
| Link | Providers |
|---|---|
| https://cert.pl/en/posts/2025/07CVE-2025-5344 |
|
Thu, 17 Jul 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 17 Jul 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Bluebird devices contain a pre-loaded barcode scanner application. This application exposes an unsecured broadcast receiver "kr.co.bluebird.android.bbsettings.BootReceiver". A local attacker can call the receiver to overwrite file containing ".json" keyword with default barcode config file. It is possible to overwrite file in any location due to lack of protection against path traversal in name of the file. This issue affects all versions before 1.3.3. | |
| Title | File removal via path traversal in unsecured broadcast receiver in Bluebird barcode scanner application | |
| Weaknesses | CWE-926 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2025-07-17T13:44:05.369Z
Reserved: 2025-05-30T06:40:16.684Z
Link: CVE-2025-5346
Updated: 2025-07-17T13:43:47.620Z
Status : Deferred
Published: 2025-07-17T13:15:23.383
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-5346
No data.
OpenCVE Enrichment
No data.
EUVD