CVE-2020-10276: Easyrobotics Er-Flex Firmware
Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.
The password for the safety PLC is the default and thus easy to find (in manuals, etc.). This allows a manipulated program to be uploaded to the safety PLC, effectively disabling the emergency stop in case an object is too close to the robot. Navigation and any other components dependent on the laser scanner are not affected (thus it is hard to detect before something happens) though the laser scanner configuration can also be affected altering further the safety of the device.
Affected products
- Easyrobotics Er-Flex Firmware: affected versions not specified
- Easyrobotics Er-Lite Firmware: affected versions not specified
- Easyrobotics Er-One Firmware: affected versions not specified
- Easyrobotics ER200 Firmware: affected versions not specified
- Mobile-Industrial-Robots MIR1000 Firmware: affected versions not specified
- Mobile-Industrial-Robots MIR100 Firmware: up to and including 2.8.1.1
- Mobile-Industrial-Robots MIR200 Firmware: affected versions not specified
- Mobile-Industrial-Robots MIR250 Firmware: affected versions not specified
- Mobile-Industrial-Robots MIR500 Firmware: affected versions not specified
- Uvd-Robots Uvd Firmware: affected versions not specified
Published 2020-06-24. Last modified 2026-06-17.