Neatorobotics
neatorobotics
7 CVEs • 16 products
Products (16)
Click to collapseToggle
Products (16)
Click to collapse
CVEs (7)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Neatorobotics 1Botvac Connected Firmware Nov 21, 2024 Jan 27, 2020 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 An issue was discovered in Neato Botvac Connected 2.2.0. The GenerateRobotPassword function of the NeatoCrypto library generates insufficiently random numbers for robot secret_key values used for local and cloud authenti...Show more |
1Neatorobotics 1Botvac Connected Firmware Nov 21, 2024 Apr 25, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A Buffer Overflow in Network::AuthenticationClient::VerifySignature in /bin/astro in Neato Botvac Connected 2.2.0 allows a remote attacker to execute arbitrary code with root privileges via a crafted POST request to a ve...Show more |
1Neatorobotics 7Botvac Connected Firmware Botvac D3 Connected FirmwareBotvac D3 Pro Connected Firmware+4 moreNov 21, 2024 Feb 23, 2019 N/A· v4 7.4 HIGH· v3 4.4 MEDIUM· v2 Secure boot bypass and memory extraction can be achieved on Neato Botvac Connected 2.2.0 devices. During startup, the AM335x secure boot feature decrypts and executes firmware. Secure boot can be bypassed by starting wit...Show more |
1Neatorobotics 1Botvac Connected Firmware Nov 21, 2024 Oct 24, 2018 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 A command injection vulnerability in the setup API in the Neato Botvac Connected 2.2.0 allows network attackers to execute arbitrary commands via shell metacharacters in the ntp field within JSON data to the /robot/initi...Show more |
1Neatorobotics 5Botvac D3 Connected Firmware Botvac D4 Connected FirmwareBotvac D5 Connected Firmware+2 moreNov 21, 2024 Sep 18, 2018 N/A· v4 5.3 MEDIUM· v3 2.9 LOW· v2 An issue was discovered on Neato Botvac Connected 2.2.0 devices. They execute unauthenticated manual drive commands (sent to /bin/webserver on port 8081) if they already have an active session. Commands like forward, bac...Show more |
1Neatorobotics 6Botvac 85 Firmware Botvac D3 Connected FirmwareBotvac D4 Connected Firmware+3 moreNov 21, 2024 Sep 18, 2018 N/A· v4 2.4 LOW· v3 2.1 LOW· v2 An issue was discovered on Neato Botvac Connected 2.2.0 and Botvac 85 1.2.1 devices. Static encryption is used for the copying of so-called "black box" logs (event logs and core dumps) to a USB stick. These logs are RC4-...Show more |
1Neatorobotics 3Botvac D4 Connected Firmware Botvac D6 Connected FirmwareBotvac D7 Connected FirmwareNov 21, 2024 Sep 18, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A replay issue was discovered on Neato Botvac Connected 2.2.0 devices. Manual control mode requires authentication, but once recorded, the authentication (always transmitted in cleartext) can be replayed to /bin/webserve...Show more |