{"id":"CVE-2021-38365","title":"Winner (aka ToneWinner) desktop speakers through 2021-08-09 allow remote attackers to recover speech signals from the power-indicator LED via a telescope and an electro-optical sensor, aka a \"Glowworm\" attack.","summary":"Winner (aka ToneWinner) desktop speakers through 2021-08-09 allow remote attackers to recover speech signals from the power-indicator LED via a telescope and an electro-optical sensor, aka a \"Glowworm\" attack.","severity":"low","cvss":3.7,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","vendor":"tonewinner","product":"winner_desktop_speakers_firmware","affected":["winner_desktop_speakers_firmware <= 2021-08-09"],"published":"2021-08-10","updated":"2026-07-05","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2021-38365","references":[{"url":"https://www.nassiben.com/glowworm-attack","label":"cve@mitre.org"},{"url":"http://www.tonewinner.com","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.nassiben.com/glowworm-attack","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.01164,"epssPercentile":0.6588,"ingestedAt":"2026-07-06T17:03:23.561Z","slug":"CVE-2021-38365","body":"## Overview\n\nWinner (aka ToneWinner) desktop speakers through 2021-08-09 allow remote attackers to recover speech signals from the power-indicator LED via a telescope and an electro-optical sensor, aka a \"Glowworm\" attack.\n\n## Affected\n\n- `winner_desktop_speakers_firmware <= 2021-08-09`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":21,"depthScoreParts":{"impact":20.4,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}