CVE-2020-10274: Easyrobotics Er-Flex Firmware
High severity, CVSS 7.1. EPSS: 0.9% chance of exploitation in the next 30 days.
The access tokens for the REST API are directly derived (sha256 and base64 encoding) from the publicly available default credentials from the Control Dashboard (refer to CVE-2020-10270 for related flaws). This flaw in combination with CVE-2020-10273 allows any attacker connected to the robot networks (wired or wireless) to exfiltrate all stored data (e.g. indoor mapping images) and associated metadata from the robot's database.
Affected products
- Easyrobotics Er-Flex Firmware: affected versions not specified
- Easyrobotics Er-Lite Firmware: affected versions not specified
- Easyrobotics Er-One Firmware: affected versions not specified
- Easyrobotics ER200 Firmware: affected versions not specified
- Mobile-Industrial-Robots MIR1000 Firmware: affected versions not specified
- Mobile-Industrial-Robots MIR100 Firmware: up to and including 2.8.1.1
- Mobile-Industrial-Robots MIR200 Firmware: affected versions not specified
- Mobile-Industrial-Robots MIR250 Firmware: affected versions not specified
- Mobile-Industrial-Robots MIR500 Firmware: affected versions not specified
- Uvd-Robots Uvd Firmware: affected versions not specified
Published 2020-06-24. Last modified 2026-06-17.