Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered on VOBOT CLOCK before 0.99.30 devices. Cleartext HTTP is used to download a breakout program, and therefore man-in-the-middle attackers can execute arbitrary code by watching for a local user to launch the Breakout Easter Egg feature, and then sending a crafted HTTP response.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
VOBOT CLOCK 安全漏洞
Vulnerability Description
VOBOT CLOCK是一款智能时钟产品。该产品具有音乐播放、语音交互和天气预报等功能。 VOBOT CLOCK 0.99.30之前版本中存在安全漏洞。攻击者可通过在用户启动Breakout Easter Egg功能之后,发送特制的HTTP请求利用该漏洞执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A