Impact
The vulnerability occurs when the handleMessageReceive function in feishu_64.go does not enforce proper authorization checks. An attacker can manipulate the input sent to this function to bypass those checks, thereby gaining unauthorized access to the Group Message Handler. This allows the attacker to read, modify, or delete group messages, resulting in confidentiality and integrity violations within the messaging system.
Affected Systems
All Sipeed PicoClaw firmware releases up to 0.2.9 are affected. The flaw resides in the Group Message Handler component of the feishu module. Any deployment of PicoClaw that includes this component is susceptible to exploitation.
Risk and Exploitability
The CVSS score of 5.3 points to medium severity, while the EPSS score of less than 1% indicates a very low predicted probability of exploitation. The vulnerability is not listed in CISA's KEV catalog. The exploit is remote, requiring network access to the message handling endpoint, and can be executed by an attacker who sends crafted data to the vulnerable function.
OpenCVE Enrichment