Neatorobotics manufactures a line of connected robotic vacuum cleaners, including the Botvac Connected and Botvac D-series models, whose vulnerability surface reflects the authentication, command-execution, and memory-safety demands of embedded networked devices. The vendor's disclosures skew toward serious outcomes, with a meaningful share reaching critical severity, and cluster around authentication bypass, OS command injection, and buffer overflow weaknesses that are characteristic of consumer IoT firmware with internet-facing control interfaces. Current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Neatorobotics over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-19442CRITICAL A Buffer Overflow in Network::AuthenticationClient::VerifySignature in /bin/astro in Neato Botvac Connected 2.2.0 allows a remote attacker to execute arbitrary code with root privi | Apr 25, 2019 | 9.8 | 32 | NO | NO |
CVE-2018-18638HIGH A command injection vulnerability in the setup API in the Neato Botvac Connected 2.2.0 allows network attackers to execute arbitrary commands via shell metacharacters in the ntp fi | Oct 24, 2018 | 8.1 | 26 | NO | NO |
CVE-2018-17176HIGH A replay issue was discovered on Neato Botvac Connected 2.2.0 devices. Manual control mode requires authentication, but once recorded, the authentication (always transmitted in cle | Sep 18, 2018 | 7.5 | 24 | NO | NO |
CVE-2018-20785HIGH Secure boot bypass and memory extraction can be achieved on Neato Botvac Connected 2.2.0 devices. During startup, the AM335x secure boot feature decrypts and executes firmware. Sec | Feb 23, 2019 | 7.4 | 23 | NO | NO |
CVE-2018-17178MEDIUM An issue was discovered on Neato Botvac Connected 2.2.0 devices. They execute unauthenticated manual drive commands (sent to /bin/webserver on port 8081) if they already have an ac | Sep 18, 2018 | 5.3 | 19 | NO | NO |
CVE-2018-19441MEDIUM An issue was discovered in Neato Botvac Connected 2.2.0. The GenerateRobotPassword function of the NeatoCrypto library generates insufficiently random numbers for robot secret_key | Jan 27, 2020 | 4.7 | 17 | NO | NO |
An issue was discovered on Neato Botvac Connected 2.2.0 and Botvac 85 1.2.1 devices. Static encryption is used for the copying of so-called "black box" logs (event logs and core du | Sep 18, 2018 | 2.4 | 14 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Neatorobotics.
Media articles that mention a CVE ID that affects a product developed by Neatorobotics — matched by CVE ID, not by vendor name.