You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
id: 3330title: 'RVD#3330: Use of Hard-coded Credentials in Robotemi Global Ltd Temi Firmware'type: Vulnerability exploitable remotelydescription: Use of Hard-coded Credentials in Robotemi Global Ltd Temi Firmware upto 20190419.165201, Launcher OS prior to 11969-13146, Robox OS prior to 117.21-119.24,and their Android phone app prior to 1.3.3-1.3.7931 allows remote attackers to gainraised privileges on the temi and have it automatically answer the attacker's calls,granting audio, video, and motor control.cwe: CWE-798cve: CVE-2020-16170keywords:
- temi, Hard-Coded Credssystem:
- Robotemi up to 20190419.165201vendor: Robotemi Global Ltdseverity:
rvss-score: 10.0rvss-vector: RVSS:1.0/AV:RN/AC:L/PR:N/UI:N/S:U/Y:O/C:H/I:H/A:H/H:Useverity-description: criticalcvss-score: 9.8cvss-vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:Hlinks:
- https://nvd.nist.gov/vuln/detail/CVE-2020-16170
- https://github.com/aliasrobotics/RVD/issues/3330flaw:
phase: runtime-operationspecificity: general issuearchitectural-location: application-specificapplication: Robox OSsubsystem: N/Apackage: N/Alanguages: N/Adate-detected: '2020-08-18'detected-by: Patxi Mayoral (Alias Robotics)detected-by-method: testing-dynamicdate-reported: '2020-08-25'reported-by: Patxi Mayoral (Alias Robotics)reported-by-relationship: security researcherissue: https://github.com/aliasrobotics/RVD/issues/3330reproducibility: alwaystrace: N/Areproduction: Not Disclosedreproduction-image: Not Disclosedexploitation:
description: Not Disclosedexploitation-image: Not Disclosedexploitation-vector: Not Disclosedexploitation-recipe: ''mitigation:
description: this issue was not acknowledged by the company yetpull-request: N/Adate-mitigation: null
The text was updated successfully, but these errors were encountered:
glerapic
changed the title
Use of Hard-coded Credentials in Robotemi Global Ltd Temi Firmware
RVD#3330: Use of Hard-coded Credentials in Robotemi Global Ltd Temi Firmware
Aug 25, 2020
The text was updated successfully, but these errors were encountered: