Alias Robotics develops autonomous mobile robot platforms for warehouse and logistics automation, with its vulnerability footprint centered on the MiR mobile robot product family and their associated firmware components. Vulnerabilities affecting this vendor skew strongly toward critical severity and recur through weakness classes that are characteristic of embedded robotics systems: hard-coded credentials, cleartext credential storage, race conditions in shared resource access, and improper access control, which collectively can undermine both the confidentiality of operational parameters and the integrity of robot behavior. Defenders deploying these platforms should prioritize access controls, network segmentation from untrusted environments, and close monitoring of vendor advisories; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Aliasrobotics over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-67511CRITICAL Cybersecurity AI (CAI) is an open-source framework for building and deploying AI-powered offensive and defensive automation. Versions 0.5.9 and below are vulnerable to Command Inje | Dec 11, 2025 | 9.6 | 33 | NO | NO |
CVE-2020-10271CRITICAL MiR100, MiR200 and other MiR robots use the Robot Operating System (ROS) default packages exposing the computational graph to all network interfaces, wireless and wired. This is th | Jun 24, 2020 | 9.8 | 27 | NO | NO |
CVE-2020-10272CRITICAL MiR100, MiR200 and other MiR robots use the Robot Operating System (ROS) default packages exposing the computational graph without any sort of authentication. This allows attackers | Jun 24, 2020 | 9.8 | 25 | NO | NO |
CVE-2020-10279CRITICAL MiR robot controllers (central computation unit) makes use of Ubuntu 16.04.2 an operating system, Thought for desktop uses, this operating system presents insecure defaults for rob | Jun 24, 2020 | 9.8 | 24 | NO | NO |
CVE-2020-10270CRITICAL Out of the wired and wireless interfaces within MiR100, MiR200 and other vehicles from the MiR fleet, it's possible to access the Control Dashboard on a hardcoded IP address. Crede | Jun 24, 2020 | 9.8 | 24 | NO | NO |
CVE-2020-10269CRITICAL One of the wireless interfaces within MiR100, MiR200 and possibly (according to the vendor) other MiR fleet vehicles comes pre-configured in WiFi Master (Access Point) mode. Creden | Jun 24, 2020 | 9.8 | 24 | NO | NO |
CVE-2020-10273HIGH MiR controllers across firmware versions 2.8.1.1 and before do not encrypt or protect in any way the intellectual property artifacts installed in the robots. This flaw allows attac | Jun 24, 2020 | 7.5 | 19 | NO | NO |
CVE-2020-10278MEDIUM The BIOS onboard MiR's Computer is not protected by password, therefore, it allows a Bad Operator to modify settings such as boot order. This can be leveraged by a Malicious operat | Jun 24, 2020 | 4.6 | 14 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Aliasrobotics.
Media articles that mention a CVE ID that affects a product developed by Aliasrobotics — matched by CVE ID, not by vendor name.