CVE-2020-10275: Easyrobotics Er-Flex Firmware
Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.
The access tokens for the REST API are directly derived from the publicly available default credentials for the web interface. Given a USERNAME and a PASSWORD, the token string is generated directly with base64(USERNAME:sha256(PASSWORD)). An unauthorized attacker inside the network can use the default credentials to compute the token and interact with the REST API to exfiltrate, infiltrate or delete data.
Affected products
- Easyrobotics Er-Flex Firmware: affected versions not specified
- Easyrobotics Er-Lite Firmware: affected versions not specified
- Easyrobotics Er-One Firmware: affected versions not specified
- Easyrobotics ER200 Firmware: affected versions not specified
- Mobile-Industrial-Robots MIR1000 Firmware: affected versions not specified
- Mobile-Industrial-Robots MIR100 Firmware: up to and including 2.8.1.1
- Mobile-Industrial-Robots MIR200 Firmware: affected versions not specified
- Mobile-Industrial-Robots MIR250 Firmware: affected versions not specified
- Mobile-Industrial-Robots MIR500 Firmware: affected versions not specified
- Uvd-Robots Uvd Firmware: affected versions not specified
Published 2020-06-24. Last modified 2026-06-17.