Impact
The vulnerability resides in the WebFetchTool.Execute function of the Guarded Web Fetch Flow component in Sipeed PicoClaw firmware up to version 0.2.9. An attacker can craft a request that causes the device to send arbitrary HTTP or HTTPS requests to externally supplied URLs, allowing the device to reach internal or external resources it normally could not access. This server‑side request forgery can reveal internal network information, trigger actions on other services, or facilitate further attacks from the compromised device.
Affected Systems
Sipeed PicoClaw devices running firmware 0.2.9 or earlier are affected. No other vendors or later firmware versions are known to be impacted as of the CNA data.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, indicating no widespread documented exploitation. The SSRF can be triggered via a remote request, meaning an attacker can potentially use the device to reach arbitrary endpoints without the device operator’s interaction, and no authentication requirement is documented in the description.
OpenCVE Enrichment