Impact
The vulnerability resides in the WebFetchTool.Execute function of the Guarded Web Fetch Flow component of Sipeed PicoClaw firmware up to version 0.2.9. An attacker can construct a request that causes the device to send arbitrary HTTP or HTTPS requests to externally supplied URLs. This server‑side request forgery can expose internal network resources or allow the device to interact with any external service it can reach over the network.
Affected Systems
Sipeed PicoClaw devices running firmware 0.2.9 or earlier are affected. No other vendors or later firmware versions are known to be impacted as of the CNA data.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of real‑world exploitation presently. The vulnerability is not listed in CISA KEV, implying no widespread documented exploitation. The SSRF can be triggered via a remote request, meaning an attacker can potentially use the device to reach arbitrary endpoints without interacting with the device operator, and no authentication requirement is explicitly documented.
OpenCVE Enrichment