CVE-2020-10285: Ufactory Xarm 5 Lite Firmware

Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.

The authentication implementation on the xArm controller has very low entropy, making it vulnerable to a brute-force attack. There is no mechanism in place to mitigate or lockout automated attempts to gain access.

Affected products

  • Ufactory Xarm 5 Lite Firmware: up to and including 1.5.0

Published 2020-07-15. Last modified 2026-06-17.