Furbo manufactures a line of internet-connected pet monitoring cameras, including the 360 and Mini models, whose firmware and cloud integration present an attack surface centered on authentication, data handling, and resource management. The recurring vulnerability classes affecting this vendor—including exposure of sensitive information, improper access control, insecure credential storage, and privilege assignment flaws—reflect the intersection of embedded firmware, remote connectivity, and user account management typical of consumer IoT devices. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Furbo over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-11646HIGH A vulnerability was detected in Tomofun Furbo 360 and Furbo Mini. This vulnerability affects unknown code of the component GATT Service. The manipulation results in improper access | Oct 12, 2025 | 8.1 | 26 | NO | NO |
CVE-2025-11643HIGH A security flaw has been discovered in Tomofun Furbo 360 and Furbo Mini. Affected by this vulnerability is an unknown functionality of the file /squashfs-root/furbo_img of the comp | Oct 12, 2025 | 8.1 | 26 | NO | NO |
CVE-2025-11636HIGH A security vulnerability has been detected in Tomofun Furbo 360 up to FB0035_FW_036. This issue affects some unknown processing of the component Account Handler. Such manipulation | Oct 12, 2025 | 8.1 | 26 | NO | NO |
CVE-2023-28704HIGH Furbo dog camera has insufficient filtering for special parameter of device log management function. An unauthenticated remote attacker in the Bluetooth network with normal user pr | Jun 2, 2023 | 8.8 | 25 | NO | NO |
CVE-2025-11649MEDIUM A vulnerability was found in Tomofun Furbo 360 and Furbo Mini. The affected element is an unknown function of the component Root Account Handler. Performing manipulation results in | Oct 12, 2025 | 6.3 | 24 | NO | NO |
CVE-2025-11648HIGH A vulnerability has been found in Tomofun Furbo 360 and Furbo Mini. Impacted is an unknown function of the file TF_FQDN.json of the component GATT Interface URL Handler. Such manip | Oct 12, 2025 | 7.4 | 24 | NO | NO |
CVE-2025-11647MEDIUM A flaw has been found in Tomofun Furbo 360 and Furbo Mini. This issue affects some unknown processing of the component GATT Service. This manipulation of the argument DeviceToken c | Oct 12, 2025 | 6.8 | 23 | NO | NO |
CVE-2025-11641MEDIUM A vulnerability was determined in Tomofun Furbo 360 and Furbo Mini. This impacts an unknown function of the component Trial Restriction Handler. This manipulation causes improper a | Oct 12, 2025 | 6.4 | 22 | NO | NO |
CVE-2025-11638MEDIUM A flaw has been found in Tomofun Furbo 360 and Furbo Mini. The affected element is an unknown function of the component Bluetooth Handler. Executing manipulation can lead to denial | Oct 12, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-11635MEDIUM A weakness has been identified in Tomofun Furbo 360 up to FB0035_FW_036. This vulnerability affects unknown code of the component File Upload. This manipulation causes resource con | Oct 12, 2025 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Furbo.
Media articles that mention a CVE ID that affects a product developed by Furbo — matched by CVE ID, not by vendor name.