VYPR

Botvac D5 Connected Firmware

by Neatorobotics

CVEs (3)

  • CVE-2018-20785HigFeb 23, 2019
    risk 0.48cvss 7.4epss 0.00

    Secure boot bypass and memory extraction can be achieved on Neato Botvac Connected 2.2.0 devices. During startup, the AM335x secure boot feature decrypts and executes firmware. Secure boot can be bypassed by starting with certain commands to the USB serial port. Although a power…

  • CVE-2018-17178MedSep 18, 2018
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered on Neato Botvac Connected 2.2.0 devices. They execute unauthenticated manual drive commands (sent to /bin/webserver on port 8081) if they already have an active session. Commands like forward, back, arc-left, arc-right, pivot-left, and pivot-right are…

  • CVE-2018-17177LowSep 18, 2018
    risk 0.16cvss 2.4epss 0.00

    An issue was discovered on Neato Botvac Connected 2.2.0 and Botvac 85 1.2.1 devices. Static encryption is used for the copying of so-called "black box" logs (event logs and core dumps) to a USB stick. These logs are RC4-encrypted with a 9-character password of *^JEd4W!I that is…