A command injection vulnerability in the setup API in the Neato Botvac Connected 2.2.0 allows network attackers to execute arbitrary commands via shell metacharacters in the ntp field within JSON data to the /robot/initialize endpoint.
References
Link | Resource |
---|---|
https://www.nccgroup.trust/us/about-us/newsroom-and-events/blog/2018/march/security-in-a-vacuum-hacking-the-neato-botvac-connected-part-1/ | Exploit Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2018-10-24T22:00:00
Updated: 2018-10-24T22:57:01
Reserved: 2018-10-24T00:00:00
Link: CVE-2018-18638
JSON object: View
NVD Information
Status : Analyzed
Published: 2018-10-24T22:29:02.043
Modified: 2019-10-03T00:03:26.223
Link: CVE-2018-18638
JSON object: View
Redhat Information
No data.
CWE