Use of Hard-coded Credentials in temi Robox OS prior to 120, temi Android app up to 1.3.7931 allows remote attackers to listen in on any ongoing calls between temi robots and their users if they can brute-force/guess a six-digit value via unspecified vectors.
References
Link | Resource |
---|---|
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/call-an-exorcist-my-robots-possessed/ | Exploit Third Party Advisory |
https://www.robotemi.com/software-updates/ | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2020-08-11 20:15
Updated : 2024-02-28 17:47
NVD link : CVE-2020-16170
Mitre link : CVE-2020-16170
CVE.ORG link : CVE-2020-16170
JSON object : View
Products Affected
robotemi
- temi
CWE
CWE-798
Use of Hard-coded Credentials