Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A replay issue was discovered on Neato Botvac Connected 2.2.0 devices. Manual control mode requires authentication, but once recorded, the authentication (always transmitted in cleartext) can be replayed to /bin/webserver on port 8081. There are no nonces, and timestamps are not checked at all.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Neato Botvac Connected 授权问题漏洞
Vulnerability Description
Neato Botvac Connected是美国Neato Robotics公司的一款吸尘机器人设备。 Neato Botvac Connected 2.2.0版本设备中存在安全漏洞,该漏洞源于手动控制模式要求身份验证,但是身份验证一旦被记录下来,在8081端口上可以将以明文方式传输的身份验证重放到/bin/webserver文件,。目前尚无此漏洞的相关信息,请随时关注CNNVD或厂商公告。
CVSS Information
N/A
Vulnerability Type
N/A