TrendMakers Sight Bulb Pro Command Injection
Published Jun 27, 2025
5.2
MEDIUMCVSS 4.0
EPSS 0.23%
Description
Unauthenticated users on an adjacent network with the Sight Bulb Pro can run shell commands as root through a vulnerable proprietary TCP protocol available on Port 16668. This vulnerability allows an attacker to run arbitrary commands on the Sight Bulb Pro by passing a well formed JSON string.
Affected products
-
Affected
- ≥ 0, ≤ 8.57.83
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| TrendMakers | Sight Bulb Pro Firmware ZJ CG32-2201 | unaffected | Affected
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
TrendMakers did not respond to CISA's request for coordination. Contact TrendMakers https://www.trendmakerscares.com/Customer-Service-Hours directly for more information.
References (3)
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data