CVE-2020-10278: Aliasrobotics MIR1000 Firmware
Medium severity, CVSS 4.6. EPSS: 1% chance of exploitation in the next 30 days.
The BIOS onboard MiR's Computer is not protected by password, therefore, it allows a Bad Operator to modify settings such as boot order. This can be leveraged by a Malicious operator to boot from a Live Image.
Affected products
- Aliasrobotics MIR1000 Firmware: up to and including 2.8.1.1
- Aliasrobotics MIR100 Firmware: up to and including 2.8.1.1
- Aliasrobotics MIR200 Firmware: up to and including 2.8.1.1
- Aliasrobotics MIR250 Firmware: up to and including 2.8.1.1
- Aliasrobotics MIR500 Firmware: up to and including 2.8.1.1
- Enabled-Robotics Er-Flex Firmware: up to and including 2.8.1.1
- Enabled-Robotics Er-Lite Firmware: up to and including 2.8.1.1
- Enabled-Robotics Er-One Firmware: up to and including 2.8.1.1
- Mobile-Industrial-Robotics ER200 Firmware: up to and including 2.8.1.1
- Uvd-Robots Uvd Robots Firmware: up to and including 2.8.1.1
Published 2020-06-24. Last modified 2026-06-17.