CVE Vulnerabilities

CVE-2019-9835

Published: Mar 15, 2019 | Modified: Nov 21, 2024
CVSS 3.x
9.6
CRITICAL
Source:
NVD
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS 2.x
5.8 MEDIUM
AV:A/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The receiver (aka bridge) component of Fujitsu Wireless Keyboard Set LX901 GK900 devices allows Keystroke Injection. This occurs because it accepts unencrypted 2.4 GHz packets, even though all legitimate communication uses AES encryption.

Affected Software

NameVendorStart VersionEnd Version
Lx901_firmwareFujitsu- (including)- (including)

References