The API on Fisher-Price Smart Toy Bear devices allows remote attackers to obtain sensitive information or modify data by leveraging presence in an 802.11 network's coverage area and entering an account number.
References
| Link | Resource |
|---|---|
| https://community.rapid7.com/community/infosec/blog/2016/02/02/security-vulnerabilities-within-fisher-price-smart-toy-hereo-gps-platform | |
| https://www.kb.cert.org/vuls/id/719736 | US Government Resource |
| https://www.kb.cert.org/vuls/id/GWAN-A6LPPW | US Government Resource |
| https://community.rapid7.com/community/infosec/blog/2016/02/02/security-vulnerabilities-within-fisher-price-smart-toy-hereo-gps-platform | |
| https://www.kb.cert.org/vuls/id/719736 | US Government Resource |
| https://www.kb.cert.org/vuls/id/GWAN-A6LPPW | US Government Resource |
Configurations
History
No history.
Information
Published : 2016-02-04 11:59
Updated : 2025-04-12 10:46
NVD link : CVE-2015-8269
Mitre link : CVE-2015-8269
CVE.ORG link : CVE-2015-8269
JSON object : View
Products Affected
fisher-price
- smart_toy_bear
CWE
CWE-287
Improper Authentication
