CVE-2020-10286: Ufactory Xarm 5 Lite Firmware

High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.

the main user account has restricted privileges but is in the sudoers group and there is not any mechanism in place to prevent sudo su or sudo -i to be run gaining unrestricted access to sensible files, encryption, or issue orders that disrupt robot operation.

Affected products

  • Ufactory Xarm 5 Lite Firmware: up to and including 1.5.0
  • Ufactory Xarm 6 Firmware: affected versions not specified
  • Ufactory Xarm 7 Firmware: affected versions not specified

Published 2020-07-15. Last modified 2026-06-17.