An issue was discovered on Zolo Halo devices via the Linkplay firmware. There is a Zolo Halo DNS rebinding attack. The device was found to be vulnerable to DNS rebinding. Combined with one of the many /httpapi.asp endpoint command-execution security issues, the DNS rebinding attack could allow an attacker to compromise the victim device from the Internet.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T00:42:03.711Z

Reserved: 2019-08-21T00:00:00

Link: CVE-2019-15312

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-07-01T20:15:10.923

Modified: 2024-11-21T04:28:25.637

Link: CVE-2019-15312

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.