CVE-2020-10285: Ufactory Xarm 5 Lite Firmware
Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.
The authentication implementation on the xArm controller has very low entropy, making it vulnerable to a brute-force attack. There is no mechanism in place to mitigate or lockout automated attempts to gain access.
Affected products
- Ufactory Xarm 5 Lite Firmware: up to and including 1.5.0
Published 2020-07-15. Last modified 2026-06-17.