Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-53605— Reachy Mini Wireless: Local Privilege Escalation via Unrestricted sudo systemctl Grant

Quick assessment

Affected
pollen-robotics reachy-mini-os
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Reachy Mini ISO for Wireless 包含使用 pi-gen 构建 Reachy Mini Wireless 机器人自定义 Raspberry Pi OS 镜像所需的文件。在版本 0.2.4 之前,Reachy Mini Wireless OS 镜像中附带了一个过于宽泛的 sudoers 配置项,允许 pollen 守护进程用户(UID 1000)无需密码即可执行 ,且未对子命令或参数进行任何限制。这构成一个本地权限提升(LPE)漏洞。任何以 pollen 用户身份运行的进程均可通过三条命令获取

CVSS 7.8 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-53605

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Reachy Mini Wireless: Local Privilege Escalation via Unrestricted sudo systemctl Grant
Source: CVE Program / CVE List V5
Vulnerability Description
Reachy Mini ISO for Wireless contains the necessary files to build a custom Raspberry Pi OS image for the Reachy Mini Wireless robot, using pi-gen. Prior to version 0.2.4, the Reachy Mini Wireless OS image shipped with an overly broad sudoers entry granting the pollen daemon user (uid 1000) passwordless sudo access to /usr/bin/systemctl with no subcommand or argument restriction. This is a local privilege escalation (LPE). Any process running as pollen can obtain full root (uid 0) on the device in three commands, with no additional vulnerability required and no user interaction. This issue has been patched in version 0.2.4.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
带着不必要的权限执行
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
pollen-robotics reachy-mini-os < 0.2.4 -

II. Public POCs for CVE-2026-53605

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-53605

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-53605 (1)

Vendor Advisories for CVE-2026-53605 (1)

Vendor Pages for CVE-2026-53605 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-53605

No comments yet


Leave a comment