CVE-2018-10825
MEDIUMMimo Baby 2 Firmware - Unauthenticated Fake Data Injection via BLE Replay or Spoofing
Title source: llmDescription
Mimo Baby 2 devices do not use authentication or encryption for the Bluetooth Low Energy (BLE) communication from a Turtle to a Lilypad, which allows attackers to inject fake information about the position and temperature of a baby via a replay or spoofing attack.
References (1)
Core 1
Core References
Various Sources x_refsource_misc
https://medium.com/%40victor_14768/mimo-baby-hack-ac7fa0ae3bfb
Scores
CVSS v3
5.3
EPSS
0.0019
EPSS Percentile
9.2%
Attack Vector
ADJACENT_NETWORK
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Details
CWE
CWE-287
CWE-311
Status
published
Products (1)
mimobaby/mimo_baby_2_firmware
Published
May 15, 2018
Tracked Since
Feb 18, 2026