Tomofun Furbo 360/Furbo Mini UART Interface Bayani fitowa

CVSS Meta Temp ScoreGarga na exploit ndiyam (≈)CTI Nganji Score
2.7$0-$5k0.00

Gundumabayani

Wuro vulnerability wey an yi classify sey karshewa an gano shi a cikin Tomofun Furbo 360 and Furbo Mini. Gaskiya, $software_function na da matsala; idan ba a sani ba, to wata aiki ce da ba a sani ba, $software_library na cikin lissafi, $software_file na cikin fayil, UART Interface na cikin sashi. Ngam manipulation shi Bayani fitowa. Wannan rauni ana sayar da shi da suna CVE-2025-11644. Ngam yiɗi laaɗi wuroo ndiyam e naange physical device. Kuma, exploit ɗin yana akwai. If you want to get the best quality for vulnerability data then you always have to consider VulDB.

Furɗebayani

Wuro vulnerability wey an yi classify sey karshewa an gano shi a cikin Tomofun Furbo 360 and Furbo Mini. Gaskiya, $software_function na da matsala; idan ba a sani ba, to wata aiki ce da ba a sani ba, $software_library na cikin lissafi, $software_file na cikin fayil, UART Interface na cikin sashi. Ngam manipulation shi Bayani fitowa. CWE shidin ka a yi bayani matsala sai ya kai CWE-922. Bug ɗin an gano shi 05/15/2025. Gaskiya, laifi an fitar da shi ta Calvin Star, Julian B (skelet4r and dead1nfluence) da Software Secured. Advisory ɗin ana rabawa don saukewa a github.com.

Wannan rauni ana sayar da shi da suna CVE-2025-11644. Ngam yiɗi laaɗi wuroo ndiyam e naange physical device. Tekinikal bayani ba ga. Kari gamji na kai hari ya fi girma. Wuro kaɗa a yi amfani da shi da sauki. Wannan vulnerability ɗin ba shi da yawa sosai. Kuma, exploit ɗin yana akwai. Yimbe ndiyam, exploit might be approx. USD $0-$5k wuro.

Á wúro huɗɗi-na-gaskiya. Wona yiwuwa a zazzage exploit a github.com.

If you want to get the best quality for vulnerability data then you always have to consider VulDB.

Kayanbayani

Nganji

Ngilabe

Sunu

CPE 2.3bayani

CPE 2.2bayani

CVSSv4bayani

VulDB Furɗo: 🔒
VulDB Gaskiya: 🔍

CNA CVSS-B Score: 🔒
CNA CVSS-BT Score: 🔒
CNA Furɗo: 🔒

CVSSv3bayani

VulDB Meta Base Score: 2.7
VulDB Meta Temp Score: 2.7

VulDB Ganda Borno: 2.0
VulDB Temp Score: 1.9
VulDB Furɗo: 🔒
VulDB Gaskiya: 🔍

NVD Ganda Borno: 4.2
NVD Furɗo: 🔒

CNA Ganda Borno: 2.0
CNA Furɗo: 🔒

CVSSv2bayani

AVACAuCIA
💳💳💳💳💳💳
💳💳💳💳💳💳
💳💳💳💳💳💳
VektarKumpleksitiAuthentisierungKariyandiGaskiyaGashina
furufurufurufurufurufuru
furufurufurufurufurufuru
furufurufurufurufurufuru

VulDB Ganda Borno: 🔒
VulDB Temp Score: 🔒
VulDB Gaskiya: 🔍

Gargajiyabayani

Klasu: Bayani fitowa
CWE: CWE-922 / CWE-200 / CWE-284
CAPEC: 🔒
ATT&CK: 🔒

Fizikal: Ee
Gumti: Ee
Gana: Ayi

Gashina: 🔒
Gada: Kə́mmbə́l
Halitta: Huɗɗi-na-gaskiya
Dawunload: 🔒

EPSS Score: 🔒
EPSS Percentile: 🔒

Furɗo farashi: 🔍
Gaskiya farashi ndiyam: 🔒

0-Dayfurufurufurufuru
Lalefurufurufurufuru

Bayani na barazanabayani

Ngam: 🔍
Akteɓe ɓernde: 🔍
Kura APT goruwa masu aiki: 🔍

Kari gamjibayani

Garga: Kumari ndiyam shikena
Halitta: 🔍

0-Day Gana: 🔒

Waktin layibayani

05/15/2025 Kari wuro anndu
06/21/2025 +37 Hənde Karamdiya ga wuro
07/03/2025 +11 Hənde Ngilabe wuro nda.
10/11/2025 +99 Hənde Advisory ganna fa.
10/11/2025 +0 Hənde VulDB gite be nayi
10/29/2025 +18 Hənde VulDB gite wuro karshe ta gyara

Ngizimbayani

Gargaaji: github.com
Ngamti: Calvin Star, Julian B (skelet4r, dead1nfluence)
Kampani: Software Secured
Halitta: A wondi feere

CVE: CVE-2025-11644 (🔒)
GCVE (CVE): GCVE-0-2025-11644
GCVE (VulDB): GCVE-100-328055
EUVD: 🔒
scip Labs: https://www.scip.ch/en/?labs.20161013

Gumtibayani

Súgá: 10/11/2025 20:38
Gargadi: 10/29/2025 21:36
Goyarwa: 10/11/2025 20:38 (55), 10/12/2025 23:07 (1), 10/12/2025 23:14 (29), 10/18/2025 09:14 (15), 10/29/2025 21:36 (12)
Gadankam: 🔍
Ngwazarma: jTag Labs
Gwamna: jTag Labs
Cache ID: 253:CDD:103

Súbítbayani

Shingilam

  • Súbít #661878: Tomofun Furbo 360, Furbo Mini Furbo 360 (≤ FB0035_FW_036), Furbo Mini (≤ MC0020_FW_074) Insecure Storage of Sensitive Information (nga jTag Labs)

Dublikat

Ganaaji

A ga wuroyo kulu. Kàlàmbe: kr + en.

Ngam loga ka, kanyi shidin dum.

Do you know our Splunk app?

Download it now for free!