CVE-2020-16170

Use of Hard-coded Credentials in temi Robox OS prior to 120, temi Android app up to 1.3.7931 allows remote attackers to listen in on any ongoing calls between temi robots and their users if they can brute-force/guess a six-digit value via unspecified vectors.
Configurations

Configuration 1 (hide)

cpe:2.3:a:robotemi:temi:*:*:*:*:*:android:*:*

History

15 May 2023, 18:56

Type Values Removed Values Added
CVSS v2 : 7.5
v3 : 9.8
v2 : 5.0
v3 : 7.5
References (MISC) https://www.mcafee.com/blogs/other-blogs/mcafee-labs/call-an-exorcist-my-robots-possessed/ - Third Party Advisory (MISC) https://www.mcafee.com/blogs/other-blogs/mcafee-labs/call-an-exorcist-my-robots-possessed/ - Exploit, Third Party Advisory

Information

Published : 2020-08-11 20:15

Updated : 2023-12-10 13:27


NVD link : CVE-2020-16170

Mitre link : CVE-2020-16170

CVE.ORG link : CVE-2020-16170


JSON object : View

Products Affected

robotemi

  • temi
CWE
CWE-798

Use of Hard-coded Credentials