CVE-2018-17177: Neatorobotics Botvac 85 Firmware

Low severity, CVSS 2.4. EPSS: 0.2% chance of exploitation in the next 30 days.

An issue was discovered on Neato Botvac Connected 2.2.0 and Botvac 85 1.2.1 devices. Static encryption is used for the copying of so-called "black box" logs (event logs and core dumps) to a USB stick. These logs are RC4-encrypted with a 9-character password of *^JEd4W!I that is obfuscated by hiding it within a custom /bin/rc4_crypt binary.

Affected products

Published 2018-09-18. Last modified 2026-06-17.