CVE-2025-5346 MEDIUM

CVE-2025-5346: File removal via path traversal in unsecured broadcast receiver in Bluebird barcode scanner application

Vendor Bluebird
Product kr.co.bluebird.android.bbsettings
Weakness CWE-926
Published July 17, 2025
Last update July 17, 2025

CVSS base score

5.1/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N

What the vulnerability does

01Description

Bluebird devices contain a pre-loaded barcode scanner application. This application exposes an unsecured broadcast receiver "kr.co.bluebird.android.bbsettings.BootReceiver". A local attacker can call the receiver to overwrite file containing ".json" keyword with default barcode config file. It is possible to overwrite file in any location due to lack of protection against path traversal in name of the file. This issue affects all versions before 1.3.3.

Key dates

02Disclosure timeline

July 17, 2025 CVE published
July 17, 2025 Record updated

Related vulnerabilities

04Related CVE