Impact
The vulnerability resides in an undocumented function within the auth.go file of Sipeed PicoClaw firmware, allowing a remote attacker to craft and submit requests that are processed with the privileges of an authenticated user. As a result, the attacker can perform any operation that the victim user is authorized to execute, potentially leading to unauthorized configuration changes, data leaks, or device disruption. The weakness is categorized as CWE‑352 and CWE‑862.
Affected Systems
Firmware versions up to and including 0.2.9 of Sipeed PicoClaw are affected. No other product variants or higher firmware releases are listed as vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity level for this CSRF flaw. The EPSS score, currently below 1 %, suggests that exploitation is unlikely at present, and the vulnerability is not listed in CISA’s KEV catalog. The bug can be triggered remotely, and a publicly disclosed exploit exists, meaning attackers could force an already‑authenticated user to perform undesired operations without the user’s knowledge. Although the flaw relies on the victim’s authenticated session, the remote nature of the attack vector means that any accessible instance of the affected firmware could be targeted, highlighting the need for timely patching.
OpenCVE Enrichment