ZeroHour

CVE-2018-18638

PoC
CVSS 3.0
8.1 high
EPSS
3%p86
Published
()
Modified
Description

A command injection vulnerability in the setup API in the Neato Botvac Connected 2.2.0 allows network attackers to execute arbitrary commands via shell metacharacters in the ntp field within JSON data to the /robot/initialize endpoint.

Vendors
neatorobotics
Products
botvac connected firmware
Weakness
CWE-78
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.