Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-11649 | 7.0 HIGH | Tomofun Furbo 360/Furbo Mini Root Account hard-coded password |
| CVE-2025-11646 | 6.3 MEDIUM | Tomofun Furbo 360/Furbo Mini GATT Service access control |
| CVE-2025-11636 | 5.6 MEDIUM | Tomofun Furbo 360 Account server-side request forgery |
| CVE-2025-11648 | 5.6 MEDIUM | Tomofun Furbo 360/Furbo Mini GATT Interface URL TF_FQDN.json server-side request forgery |
| CVE-2025-11635 | 4.3 MEDIUM | Tomofun Furbo 360 File Upload resource consumption |
| CVE-2025-11638 | 4.3 MEDIUM | Tomofun Furbo 360/Furbo Mini Bluetooth denial of service |
| CVE-2025-11642 | 4.0 MEDIUM | Tomofun Furbo 360/Furbo Mini Registration denial of service |
| CVE-2025-11641 | 3.9 LOW | Tomofun Furbo 360/Furbo Mini Trial Restriction access control |
| CVE-2025-11633 | 3.7 LOW | Tomofun Furbo 360/Furbo Mini HTTP Traffic collect_logs.sh upload_file_to_s3 certificate va |
| CVE-2025-11643 | 3.7 LOW | Tomofun Furbo 360/Furbo Mini MQTT Client Certificate furbo_img hard-coded credentials |
| CVE-2025-11639 | 3.3 LOW | Tomofun Furbo 360/Furbo Mini Debug Log S3 Bucket collect_logs.sh sensitive information |
| CVE-2025-11647 | 3.1 LOW | Tomofun Furbo 360/Furbo Mini GATT Service information disclosure |
| CVE-2025-11640 | 3.1 LOW | Tomofun Furbo 360/Furbo Mini Bluetooth Low Energy cleartext transmission |
| CVE-2025-11634 | 2.4 LOW | Tomofun Furbo 360/Furbo Mini UART information disclosure |
| CVE-2025-11645 | 2.4 LOW | Tomofun Furbo Mobile App Authentication Token sensitive information |
| CVE-2025-11644 | 2.0 LOW | Tomofun Furbo 360/Furbo Mini UART sensitive information |
| CVE-2025-11650 | 1.8 LOW | Tomofun Furbo 360/Furbo Mini Password shadow weak hash |
No comments yet