Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Furbo 360 — Vulnerabilities & Security Advisories 17

All 17 CVE vulnerabilities found in Furbo 360, with AI-generated Chinese analysis, references, and POCs.

This page details vulnerability aggregations for the Furbo 360 device, focusing on general security weaknesses within the product ecosystem. It compiles a comprehensive list of reported security flaws affecting the Furbo 360 smart pet camera and its associated software infrastructure. The collection spans from the product’s initial market release through recent security updates, ensuring a chronological view of emerging threats and resolved issues. By reviewing these records, users can track the vendor’s advisory history to understand how quickly security patches are deployed for firmware and app updates. The data also allows for a deeper understanding of specific weakness classes that commonly impact Internet of Things devices, such as authentication bypasses, data exposure risks, or firmware integrity failures. Readers can look up the Furbo 360’s specific vulnerability history to assess the long-term security posture of the hardware and determine if their units remain exposed to known exploits. This resource serves as a neutral archive for security researchers, IT administrators, and concerned pet owners who need to evaluate the safety of their connected devices. It provides context on the frequency and severity of incidents without sensationalizing the risks or offering promotional content. The aim is to facilitate informed decision-making regarding device maintenance, network segmentation, and the necessity of replacing or updating hardware to mitigate ongoing threats in the smart home environment.

Vendor: Tomofun

CVE IDTitleCVSSSeverityPublished
CVE-2025-11650 Tomofun Furbo 360/Furbo Mini Password shadow weak hash CWE-328 1.8 Low2025-10-12
CVE-2025-11649 Tomofun Furbo 360/Furbo Mini Root Account hard-coded password CWE-259 7.0 High2025-10-12
CVE-2025-11648 Tomofun Furbo 360/Furbo Mini GATT Interface URL TF_FQDN.json server-side request forgery CWE-918 5.6 Medium2025-10-12
CVE-2025-11647 Tomofun Furbo 360/Furbo Mini GATT Service information disclosure CWE-200 3.1 Low2025-10-12
CVE-2025-11646 Tomofun Furbo 360/Furbo Mini GATT Service access control CWE-284 6.3 Medium2025-10-12
CVE-2025-11644 Tomofun Furbo 360/Furbo Mini UART sensitive information CWE-922 2.0 Low2025-10-12
CVE-2025-11643 Tomofun Furbo 360/Furbo Mini MQTT Client Certificate furbo_img hard-coded credentials CWE-798 3.7 Low2025-10-12
CVE-2025-11642 Tomofun Furbo 360/Furbo Mini Registration denial of service CWE-404 4.0 Medium2025-10-12
CVE-2025-11641 Tomofun Furbo 360/Furbo Mini Trial Restriction access control CWE-284 3.9 Low2025-10-12
CVE-2025-11640 Tomofun Furbo 360/Furbo Mini Bluetooth Low Energy cleartext transmission CWE-319 3.1 Low2025-10-12
CVE-2025-11639 Tomofun Furbo 360/Furbo Mini Debug Log S3 Bucket collect_logs.sh sensitive information CWE-922 3.3 Low2025-10-12
CVE-2025-11638 Tomofun Furbo 360/Furbo Mini Bluetooth denial of service CWE-404 4.3 Medium2025-10-12
CVE-2025-11637 Tomofun Furbo 360 Audio race condition CWE-362 4.3 Medium2025-10-12
CVE-2025-11636 Tomofun Furbo 360 Account server-side request forgery CWE-918 5.6 Medium2025-10-12
CVE-2025-11635 Tomofun Furbo 360 File Upload resource consumption CWE-400 4.3 Medium2025-10-12
CVE-2025-11634 Tomofun Furbo 360/Furbo Mini UART information disclosure CWE-200 2.4 Low2025-10-12
CVE-2025-11633 Tomofun Furbo 360/Furbo Mini HTTP Traffic collect_logs.sh upload_file_to_s3 certificate validation CWE-295 3.7 Low2025-10-12

All 17 known CVE vulnerabilities affecting Furbo 360 with full Chinese analysis, references, and POCs where available.