CNNVD-202510-1587 Information

CNNVD ID

CNNVD-202510-1587

CVE-2025-11650

  • CNNVD Published: 2025-10-12

Description (Chinese)

Tomofun Furbo 360和Tomofun Furbo Mini都是中国台湾Tomofun公司的一款智能宠物摄像机。 Tomofun Furbo 360 FB0035_FW_036及之前版本和Tomofun Furbo Mini MC0020_FW_074及之前版本存在安全漏洞,该漏洞源于密码处理组件中文件/etc/shadow使用弱哈希,可能导致物理设备攻击。

Description (English)

Tomofun Furbo 360 and Tomofun Furbo Mini are smart pet cameras from Tomofun, Taiwan, China. Tomofun Furbo 360 FB0035 FW 036 et seq. and Tomofun Furbo Mini MC0020 FW 074 et seq. have a security loophole, which stems from the use of weak Hashi in the password processing component, which may result in physical equipment attacks.

Hazard Level

Critical

Vulnerability Type

其他

Affected Vendor

Tomofun

Published

2025-10-12

Last Modified

2026-02-24

References

https://github.com/dead1nfluence/Furbo-Advisories/blob/main/Insecure-Encryption-Algorithm.md https://vuldb.com/?submit.662771 https://vuldb.com/?id.328061 https://vuldb.com/?ctiid.328061 https://access.redhat.com/security/cve/cve-2025-11650

Share on: