A command injection vulnerability in the setup API in the Neato Botvac Connected 2.2.0 allows network attackers to execute arbitrary commands via shell metacharacters in the ntp field within JSON data to the /robot/initialize endpoint.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2018-10-24T22:00:00
Updated: 2024-08-05T11:15:59.888Z
Reserved: 2018-10-24T00:00:00
Link: CVE-2018-18638
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-10-24T22:29:02.043
Modified: 2024-11-21T03:56:16.657
Link: CVE-2018-18638
Redhat
No data.