CVE-2020-10277: Easyrobotics Er-Flex Firmware
Medium severity, CVSS 6.4. EPSS: 0.4% chance of exploitation in the next 30 days.
There is no mechanism in place to prevent a bad operator to boot from a live OS image, this can lead to extraction of sensible files (such as the shadow file) or privilege escalation by manually adding a new user with sudo privileges on the machine.
Affected products
- Easyrobotics Er-Flex Firmware: affected versions not specified
- Easyrobotics Er-Lite Firmware: affected versions not specified
- Easyrobotics Er-One Firmware: affected versions not specified
- Easyrobotics ER200 Firmware: affected versions not specified
- Mobile-Industrial-Robots MIR1000 Firmware: affected versions not specified
- Mobile-Industrial-Robots MIR100 Firmware: up to and including 2.8.1.1
- Mobile-Industrial-Robots MIR200 Firmware: affected versions not specified
- Mobile-Industrial-Robots MIR250 Firmware: affected versions not specified
- Mobile-Industrial-Robots MIR500 Firmware: affected versions not specified
- Uvd-Robots Uvd Firmware: affected versions not specified
Published 2020-06-24. Last modified 2026-06-17.