Impact
The vulnerability is in the First Setup component's access_control.go module of Sipeed PicoClaw firmware versions up to 0.2.9. Manipulating the allowed_cidrs argument allows an unauthenticated attacker to use an alternate communication channel and bypass authentication checks. This flaw is an authentication bypass (CWE‑287) that could enable unauthorized control over the device, compromising confidentiality, integrity, or availability if an attacker gains privileged access. The exploit is considered difficult but is publicly available.
Affected Systems
The affected system is Sipeed's PicoClaw microcontroller board running firmware version 0.2.9 or earlier. The flaw resides in the web/backend/middleware/access_control.go component of the First Run Setup. All releases prior to 0.2.9 are impacted; newer revisions that include the patch commit are not.
Risk and Exploitability
The CVSS score is 6.3, indicating moderate severity, and the EPSS score is below 1 %, suggesting a low probability of widespread exploitation. The vulnerability is not listed in CISA KEV. Attack complexity is high and exploitation is difficult, but remote exploitation is possible through the web interface. The overall risk is moderate, warranting timely remediation.
OpenCVE Enrichment