CVE-2020-10286: Ufactory Xarm 5 Lite Firmware
High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.
the main user account has restricted privileges but is in the sudoers group and there is not any mechanism in place to prevent sudo su or sudo -i to be run gaining unrestricted access to sensible files, encryption, or issue orders that disrupt robot operation.
Affected products
- Ufactory Xarm 5 Lite Firmware: up to and including 1.5.0
- Ufactory Xarm 6 Firmware: affected versions not specified
- Ufactory Xarm 7 Firmware: affected versions not specified
Published 2020-07-15. Last modified 2026-06-17.