CVE-2018-10825
MEDIUMMimobaby Mimo Baby 2 Firmware - Authentication Bypass
Title source: ruleDescription
Mimo Baby 2 devices do not use authentication or encryption for the Bluetooth Low Energy (BLE) communication from a Turtle to a Lilypad, which allows attackers to inject fake information about the position and temperature of a baby via a replay or spoofing attack.
Scores
CVSS v3
5.3
EPSS
0.0002
EPSS Percentile
5.1%
Attack Vector
ADJACENT_NETWORK
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Details
CWE
CWE-287
CWE-311
Status
published
Products (1)
mimobaby/mimo_baby_2_firmware
Published
May 15, 2018
Tracked Since
Feb 18, 2026