CVE-2024-52876

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Nov 17, 2024
Updated: Nov 18, 2024
CWE ID 125

Summary

CVE-2024-52876 is a vulnerability affecting the Holy Stone Remote ID Module HSRID01, which is used with the Drone Go2 mobile application. The issue stems from outdated firmware, specifically versions prior to 1.1.8. An attacker can exploit this vulnerability by sending multiple read requests to the ASTM Remote ID (0xFFFA) GATT service in broadcast mode. Successful exploitation enables unauthenticated "remote power off" actions, posing a significant security risk. Users are advised to update their firmware to the latest version to mitigate this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share