Impact
The flaw resides in the IPAllowlist routine of the Launcher component’s access_control.go file. By manipulating the function, an attacker can override configured IP restrictions and gain unauthorised access to the PicoClaw’s web backend. This bypass allows any remote user to reach the management interface without needing prior credentials, potentially exposing sensitive configuration options.
Affected Systems
Sipeed PicoClaw devices running firmware versions 0.2.9 or older are affected. The vulnerability is confined to the Launcher module’s web/backend/middleware/access_control.go file and does not involve any other components of the firmware.
Risk and Exploitability
The CVSS score of 6.9 places the issue in the moderate‑to‑high severity range. The EPSS score of less than 1% suggests that exploitation is currently unlikely in the wild, but the vulnerability is publicly disclosed and an exploit is available. The issue is not listed in CISA’s KEV catalogue. Attackers would need only network access to the device, with no additional authentication, to exploit the bypass.
OpenCVE Enrichment