Impact
A weakness in the web_fetch function of Sipeed PicoClaw’s pkg/tools/integration/web.go allows an attacker to provoke the device to send HTTP requests to arbitrary targets. This exploitation can reveal internal services, exfiltrate data, or launch further attacks from the compromised device. The flaw is a form of input validation error, categorized as CWE‑918.
Affected Systems
All PicoClaw devices running firmware version 0.2.9 or earlier are affected. The vulnerability is exposed through the publicly reachable web interface; any installation that has not yet applied the patch identified in commit c15aac21fe05ee103a470e1104bc891754e83392 remains vulnerable.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate‑to‑high severity, while the EPSS score of less than 1 % points to a low current exploitation likelihood. The issue is not listed in the CISA KEV catalog. Remote exploitation is feasible via the device’s web interface, requiring only network connectivity to the PicoClaw. Organizations should prioritize patch deployment to mitigate this SSRF risk.
OpenCVE Enrichment