Critical severity9.8NVD Advisory· Published Jun 24, 2020· Updated Jun 17, 2026
CVE-2020-10275
CVE-2020-10275
Description
The access tokens for the REST API are directly derived from the publicly available default credentials for the web interface. Given a USERNAME and a PASSWORD, the token string is generated directly with base64(USERNAME:sha256(PASSWORD)). An unauthorized attacker inside the network can use the default credentials to compute the token and interact with the REST API to exfiltrate, infiltrate or delete data.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
12- Mobile Industrial Robots A/S/MiR100v5Range: v2.8.1.1 and before
- cpe:2.3:o:mobile-industrial-robots:mir100_firmware:*:*:*:*:*:*:*:*Range: <=2.8.1.1
- cpe:2.3:o:mobile-industrial-robots:mir200_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:mobile-industrial-robots:mir250_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:mobile-industrial-robots:mir500_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:mobile-industrial-robots:mir1000_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:easyrobotics:er200_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:easyrobotics:er-lite_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:easyrobotics:er-flex_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:easyrobotics:er-one_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:uvd-robots:uvd_firmware:-:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- github.com/aliasrobotics/RVD/issues/2565nvdThird Party Advisory
News mentions
0No linked articles in our index yet.