ZeroHour

Vulnerabilities

3 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-10285
+1 in the same advisory: …10286
The authentication implementation on the xArm controller has very low entropy, making it vulnerable to a brute-force attack.

The authentication implementation on the xArm controller has very low entropy, making it vulnerable to a brute-force attack. There is no mechanism in place to mitigate or lockout automated attempts to gain access.

NVD description · AI analysis pending
9.8
group max
1%
  • ufactory xarm 5 lite firmware
CVE-2020-10284
No authentication is required to control the robot inside the network, moreso the latest available user manual shows an option that lets the user to add a passw

No authentication is required to control the robot inside the network, moreso the latest available user manual shows an option that lets the user to add a password to the robot but as in xarm_studio 1.3.0 the option is missing from the menu. Assuming manual control, even by forcefully removing the current operator from an active session.

NVD description · AI analysis pending
9.11%
  • ufactory xarm studio