CVE-2025-11646

MEDIUM

Furbo 360 Dog Camera Firmware < 036 and Furbo Mini Firmware < 074 - Improper Access Controls in GATT Service

Title source: llm
STIX 2.1

Description

A vulnerability was detected in Tomofun Furbo 360 and Furbo Mini. This vulnerability affects unknown code of the component GATT Service. The manipulation results in improper access controls. The attack can only be performed from the local network. The exploit is now public and may be used. The firmware versions determined to be affected are Furbo 360 up to FB0035_FW_036 and Furbo Mini up to MC0020_FW_074. The vendor was contacted early about this disclosure but did not respond in any way.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.328057
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.328057
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.661900

Scores

CVSS v3 6.3
EPSS 0.0050
EPSS Percentile 38.8%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-266 CWE-284
Status published
Products (2)
furbo/furbo_360_dog_camera_firmware < 036
furbo/furbo_mini_firmware < 074
Published Oct 12, 2025
Tracked Since Feb 18, 2026