CVE-2018-19441 describes an insufficient randomness vulnerability in the NeatoCrypto library used by Neato Botvac Connected 2.2.0. The GenerateRobotPassword function creates weak secret_key values for local and cloud authentication, relying solely on the robot's serial number and estimated provisioning time, which can be brute-forced by an attacker. This vulnerability has a CVSS score of 4.7 (Medium), indicating a local attack vector with high attack complexity, requiring prior knowledge of the serial number and provisioning time. Successful exploitation could lead to high confidentiality impact by allowing an attacker to gain unauthorized access to the robot. There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.2.0CPE matchmatch criteria | cpe:2.3:o:neatorobotics:botvac_connected_firmware:2.2.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.