Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

4 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.4)0.47%—Neatorobotics Botvac D4 Connected FirmwareNeatorobotics Botvac D6 Connected FirmwareNeatorobotics Botvac D5 Connected FirmwareNeatorobotics Botvac D7 Connected Firmware+323/2/201917/6/2026
Secure boot bypass and memory extraction can be achieved on Neato Botvac Connected 2.2.0 devices. During startup, the AM335x secure boot feature decrypts and executes firmware. Secure boot can be bypassed by starting with certain commands to the USB serial port. Although a power cycle occurs, this does not completely…
ModificadaMedia (5.3)0.68%—Neatorobotics Botvac D4 Connected FirmwareNeatorobotics Botvac D6 Connected FirmwareNeatorobotics Botvac D5 Connected FirmwareNeatorobotics Botvac D7 Connected Firmware+118/9/201817/6/2026
An issue was discovered on Neato Botvac Connected 2.2.0 devices. They execute unauthenticated manual drive commands (sent to /bin/webserver on port 8081) if they already have an active session. Commands like forward, back, arc-left, arc-right, pivot-left, and pivot-right are executed even though the web socket replies…
ModificadaBaja (2.4)0.17%—Neatorobotics Botvac D4 Connected FirmwareNeatorobotics Botvac D6 Connected FirmwareNeatorobotics Botvac D5 Connected FirmwareNeatorobotics Botvac D7 Connected Firmware+218/9/201817/6/2026
An issue was discovered on Neato Botvac Connected 2.2.0 and Botvac 85 1.2.1 devices. Static encryption is used for the copying of so-called "black box" logs (event logs and core dumps) to a USB stick. These logs are RC4-encrypted with a 9-character password of *^JEd4W!I that is obfuscated by hiding it within a custom…
ModificadaAlta (7.5)1.0%—Neatorobotics Botvac D4 Connected FirmwareNeatorobotics Botvac D6 Connected FirmwareNeatorobotics Botvac D7 Connected Firmware18/9/201817/6/2026
A replay issue was discovered on Neato Botvac Connected 2.2.0 devices. Manual control mode requires authentication, but once recorded, the authentication (always transmitted in cleartext) can be replayed to /bin/webserver on port 8081. There are no nonces, and timestamps are not checked at all.
Orbitaley — Vulnerabilidades