Vivi Receiver Release 3.9.4 / App Release 3.9.4 (Optional)
Vivi Firmware Version 3.9.4 is 3.9.1 with additional security patches applied.
We are still investigating stability issues with 3.9.2, this is an interim release to address specific security vulnerabilities that have been raised since 3.9.1.
What’s changed?
Fixed a security vulnerability that allows the session ID to be highjacked, potentially leaving the box vulnerable to a DDoS attack from the internal network.
Fixed a security vulnerability that allowed the box API to be manipulated enabling a user to bypass the room code to join a room and potentially take screen shots.
Who does this affect?
All users on the firmware version 3.9.1 or earlier.
Who should update to this release?
All users on the firmware version 3.9.1 or earlier who are concerned that the security vulnerabilities could be exploited in their environment.
We always recommend that you test new releases in your environment before rolling out organization wide.