CVE-2020-10272
CRITICALMiR Robot Firmware < 2.8.1.1 - Unauthenticated Remote Control via ROS Default Packages
Title source: llmDescription
MiR100, MiR200 and other MiR robots use the Robot Operating System (ROS) default packages exposing the computational graph without any sort of authentication. This allows attackers with access to the internal wireless and wired networks to take control of the robot seamlessly. In combination with CVE-2020-10269 and CVE-2020-10271, this flaw allows malicious actors to command the robot at desire.
References (1)
Core 1
Core References
Exploit, Third Party Advisory x_refsource_confirm
https://github.com/aliasrobotics/RVD/issues/2554
Scores
CVSS v3
9.8
EPSS
0.0246
EPSS Percentile
82.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-306
Status
published
Products (10)
aliasrobotics/mir1000_firmware
< 2.8.1.1
aliasrobotics/mir100_firmware
< 2.8.1.1
aliasrobotics/mir200_firmware
< 2.8.1.1
aliasrobotics/mir250_firmware
< 2.8.1.1
aliasrobotics/mir500_firmware
< 2.8.1.1
enabled-robotics/er-flex_firmware
< 2.8.1.1
enabled-robotics/er-lite_firmware
< 2.8.1.1
enabled-robotics/er-one_firmware
< 2.8.1.1
mobile-industrial-robotics/er200_firmware
< 2.8.1.1
uvd-robots/uvd_robots_firmware
< 2.8.1.1
Published
Jun 24, 2020
Tracked Since
Feb 18, 2026