Vecna develops mobile robotics and autonomous systems, with its vulnerability footprint centered on the VGO remote-presence robot and its firmware. The observed weakness classes reflect common patterns in connected device software: insufficient information density in public disclosures, exposure of sensitive information, access-control and authorization gaps, and OS command-injection vectors in device management interfaces. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vecna over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-8858CRITICAL If an attacker has access to the firmware from the VGo Robot (Versions 3.0.3.52164 and 3.0.3.53662. Prior versions may also be affected) they may be able to extract credentials. | Oct 30, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-17933HIGH VGo Robot (Versions 3.0.3.52164 and 3.0.3.53662. Prior versions may also be affected) connected to the VGo XAMPP. User accounts may be able to execute commands that are outside the | Oct 30, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-8866HIGH In Vecna VGo Robot versions prior to 3.0.3.52164, an attacker on an adjacent network could perform command injection. | May 9, 2018 | 8.8 | 26 | NO | NO |
CVE-2018-17931MEDIUM If an attacker has physical access to the VGo Robot (Versions 3.0.3.52164 and 3.0.3.53662. Prior versions may also be affected) they may be able to alter scripts, which may allow c | Oct 30, 2018 | 6.8 | 22 | NO | NO |
CVE-2018-8860MEDIUM In Vecna VGo Robot versions prior to 3.0.3.52164, an attacker may be able to capture firmware updates through the adjacent network. | May 9, 2018 | 6.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vecna.
Media articles that mention a CVE ID that affects a product developed by Vecna — matched by CVE ID, not by vendor name.