Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
4 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.7) | 0.30% | — | Neatorobotics Botvac Connected Firmware | 27/1/2020 | 17/6/2026 | An issue was discovered in Neato Botvac Connected 2.2.0. The GenerateRobotPassword function of the NeatoCrypto library generates insufficiently random numbers for robot secret_key values used for local and cloud authentication/authorization. If an attacker knows the serial number and is able to estimate the time of… | |
| Modificada | Crítica (9.8) | 7.5% | — | Neatorobotics Botvac Connected Firmware | 25/4/2019 | 17/6/2026 | A Buffer Overflow in Network::AuthenticationClient::VerifySignature in /bin/astro in Neato Botvac Connected 2.2.0 allows a remote attacker to execute arbitrary code with root privileges via a crafted POST request to a vendors/neato/robots/[robot_serial]/messages Neato cloud URI on the nucleo.neatocloud.com web site… | |
| Modificada | Alta (7.4) | 0.47% | — | Neatorobotics Botvac D4 Connected FirmwareNeatorobotics Botvac D6 Connected FirmwareNeatorobotics Botvac D5 Connected FirmwareNeatorobotics Botvac D7 Connected Firmware+3 | 23/2/2019 | 17/6/2026 | Secure boot bypass and memory extraction can be achieved on Neato Botvac Connected 2.2.0 devices. During startup, the AM335x secure boot feature decrypts and executes firmware. Secure boot can be bypassed by starting with certain commands to the USB serial port. Although a power cycle occurs, this does not completely… | |
| Modificada | Alta (8.1) | 2.8% | — | Neatorobotics Botvac Connected Firmware | 24/10/2018 | 17/6/2026 | A command injection vulnerability in the setup API in the Neato Botvac Connected 2.2.0 allows network attackers to execute arbitrary commands via shell metacharacters in the ntp field within JSON data to the /robot/initialize endpoint. |