Impact
The vulnerability resides in the webhook.ParseRequest function of the LINE Webhook component in Sipeed PicoClaw. It allows an attacker to bypass authentication by replaying a previously captured valid request, thereby gaining unauthorized access to the webhook's functionality. The flaw is rooted in improper authentication validation and a lack of protection against replayed traffic.
Affected Systems
Sipeed PicoClaw releases up to and including version 0.2.9 are affected. Versions beyond 0.2.9 are presumed to contain the correction, though the specific release that implements the fix is not documented in the source data.
Risk and Exploitability
The CVSS score of 6.9 classifies the issue as moderate severity, while the EPSS score of less than 1% indicates a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. It can be exploited remotely through the webhook endpoint, and public exploit code is available. An attacker who captures a legitimate request can replay it to achieve unauthorized access, but widespread exploitation evidence is absent, and the low EPSS suggests that immediate threat is modest.
OpenCVE Enrichment