Intumit develops the SmartRobot automation platform and associated firmware, a narrowly scoped product line that presents an attack surface centered on web application and code-execution mechanics. The recurring vulnerability classes affecting this vendor cluster around input handling and injection risks—code injection, cross-site scripting, generic injection, server-side request forgery, and hard-coded cryptographic keys—reflecting typical exposure in automation and robotics control systems. Current severity, exploitation activity, and detailed exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Intumit over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-2413CRITICAL Intumit SmartRobot uses a fixed encryption key for authentication. Remote attackers can use this key to encrypt a string composed of the user's name and timestamp to generate an au | Mar 13, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-0552CRITICAL Intumit inc. SmartRobot's web framwork has a remote code execution vulnerability. An unauthorized remote attacker can exploit this vulnerability to execute arbitrary commands on th | Jan 15, 2024 | 9.8 | 24 | NO | NO |
CVE-2025-3572HIGH SmartRobot from INTUMIT has a Server-Side Request Forgery vulnerability, allowing unauthenticated remote attackers to probe internal network and even access arbitrary local files o | Apr 14, 2025 | 7.5 | 22 | NO | NO |
CVE-2024-12652HIGH A Improper Control of Generation of Code ('Code Injection') vulnerability in groovy script function in SmartRobot′s Conversational AI Platform before v7.2.0 allows remote authentic | Dec 26, 2024 | 8.8 | 22 | NO | NO |
CVE-2024-8776MEDIUM SmartRobot from INTUMIT does not properly validate a specific page parameter, allowing unautheticated remote attackers to inject JavaScript code to the parameter for Reflected Cros | Sep 16, 2024 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Intumit.
Media articles that mention a CVE ID that affects a product developed by Intumit — matched by CVE ID, not by vendor name.