Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Sipeed — Vulnerabilities & Security Advisories 14

Browse all 14 CVE security advisories affecting Sipeed. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page aggregates security vulnerabilities associated with the hardware vendor Sipeed, categorized by product line and weakness type. It collects advisories related to Sipeed’s development boards, single-board computers, and related firmware, covering incidents reported over the past several years. Readers can use this resource to track the vendor’s security advisories, understand recurring weakness classes such as unpatched firmware flaws or insecure network interfaces, and review the vulnerability history of specific Sipeed products. The collection is organized to facilitate comparative analysis and long-term monitoring of the vendor’s security posture, without relying on marketing language or exhaustive lists of individual CVE identifiers.

Top products by Sipeed: PicoClaw NanoKVM
CVE ID Title CVSS Severity Published
CVE-2026-16198 Sipeed PicoClaw First Run Setup access_control.go authentication bypass — PicoClaw CWE-288 5.6 Medium 2026-07-18
CVE-2026-16197 Sipeed PicoClaw Group Message feishu_64.go handleMessageReceive authorization — PicoClaw CWE-862 6.3 Medium 2026-07-18
CVE-2026-16196 Sipeed PicoClaw web_fetch web.go isPrivateOrRestrictedIP server-side request forgery — PicoClaw CWE-918 6.3 Medium 2026-07-18
CVE-2026-16195 Sipeed PicoClaw Group Message wecom.go dispatchIncoming authorization — PicoClaw CWE-863 6.3 Medium 2026-07-18
CVE-2026-16085 Sipeed PicoClaw context.go NewContextBuilder inclusion of functionality from untrusted control sphere — PicoClaw CWE-829 5.3 Medium 2026-07-18
CVE-2026-16084 Sipeed PicoClaw web.go web_fetch server-side request forgery — PicoClaw CWE-918 7.3 High 2026-07-18
CVE-2026-16083 Sipeed PicoClaw LINE Webhook line.go webhook.ParseRequest authentication replay — PicoClaw CWE-294 5.3 Medium 2026-07-18
CVE-2026-16082 Sipeed PicoClaw pipeline_execute.go ExecTool.executeRun toctou — PicoClaw CWE-367 5.3 Medium 2026-07-18
CVE-2026-16081 Sipeed PicoClaw auth.go cross-site request forgery — PicoClaw CWE-352 4.3 Medium 2026-07-18
CVE-2026-15320 Sipeed PicoClaw pico.go rt.ReloadConfig authorization — PicoClaw CWE-862 5.4 Medium 2026-07-10
CVE-2026-15319 Sipeed PicoClaw Launcher access_control.go IPAllowlist access control — PicoClaw CWE-284 7.3 High 2026-07-10
CVE-2026-15318 Sipeed PicoClaw MQTT Channel mqtt.go authorization — PicoClaw CWE-863 6.3 Medium 2026-07-10
CVE-2026-15317 Sipeed PicoClaw Guarded Web Fetch Flow web.go WebFetchTool.Execute server-side request forgery — PicoClaw CWE-918 6.3 Medium 2026-07-10
CVE-2026-32296 Sipeed NanoKVM unauthenticated Wi-Fi configuration endpoint — NanoKVM CWE-306 8.2 High 2026-03-17

This page lists every published CVE security advisory associated with Sipeed. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.