An issue was discovered in Lush 2 through 2020-02-25. Due to the lack of Bluetooth traffic encryption, it is possible to hijack an ongoing Bluetooth connection between the Lush 2 and a mobile phone. This allows an attacker to gain full control over the device.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://seclists.org/fulldisclosure/2024/Jul/14 | mailing list |