PT-2020-14788 · Temi · Temi Robox Os+1
Mark Bereza
·
Published
2020-08-07
·
Updated
2020-09-02
·
CVE-2020-16167
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
temi Robox OS versions prior to 120
temi Android app versions up to 1.3.7931
Description
The issue allows remote attackers to receive and answer calls intended for another temi user, granting motor control of the temi in addition to audio/video access. This is possible due to missing authentication for a critical function.
Recommendations
For temi Robox OS versions prior to 120, update to version 120 or later to resolve the issue.
For temi Android app versions up to 1.3.7931, update to a version later than 1.3.7931 to fix the problem.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Temi Android App
Temi Robox Os