Cognitoys develops educational smart-toy products, including the Stemosaur and its associated firmware, with a modest vulnerability footprint centered on information-disclosure and cryptographic-implementation weaknesses. The observed flaw classes reflect the challenge of securing connected devices with embedded secrets and wireless communication channels; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cognitoys over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-8867MEDIUM Elemental Path's CogniToys Dino smart toys through firmware version 0.0.794 use AES-128 with ECB mode to encrypt voice traffic between the device and remote server, allowing a mali | Dec 11, 2017 | 5.9 | 21 | NO | NO |
CVE-2017-8865MEDIUM Elemental Path's CogniToys Dino smart toys through firmware version 0.0.794 do not provide sufficient protections against capture-replay attacks, allowing an attacker on the networ | Dec 11, 2017 | 5.9 | 21 | NO | NO |
CVE-2017-8866MEDIUM Elemental Path's CogniToys Dino smart toys through firmware version 0.0.794 share a fixed small pool of hardcoded keys, allowing a remote attacker to use a different Dino device to | Dec 11, 2017 | 5.9 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cognitoys.
Media articles that mention a CVE ID that affects a product developed by Cognitoys — matched by CVE ID, not by vendor name.