CVE-2024-52876
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Nov 17, 2024
Updated: Nov 18, 2024
CWE ID 125
Summary
CVE-2024-52876 is a vulnerability affecting the Holy Stone Remote ID Module HSRID01, which is used with the Drone Go2 mobile application. The issue stems from outdated firmware, specifically versions prior to 1.1.8. An attacker can exploit this vulnerability by sending multiple read requests to the ASTM Remote ID (0xFFFA) GATT service in broadcast mode. Successful exploitation enables unauthenticated "remote power off" actions, posing a significant security risk. Users are advised to update their firmware to the latest version to mitigate this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Drone Go2 Mobile Application