Impact
The vulnerability resides in the operating system image for the Reachy Mini Wireless robot. Because the sudoers file contains an overly broad rule, the pollen daemon user (uid 1000) can invoke /usr/bin/systemctl with passwordless sudo access and no restriction on subcommands. A local process running as that user can thus elevate to root in a single command, giving full control over the device. This weakness is mapped to CWE‑250 and CWE‑269.
Affected Systems
All Reachy Mini Wireless OS images shipped by pollen-robotics before version 0.2.4 are affected. The issue was fixed in the 0.2.4 release, which removes the unrestricted sudoers entry for /usr/bin/systemctl.
Risk and Exploitability
With a CVSS score of 7.8, the vulnerability carries a high local impact. The attack requires only local access and no additional vulnerabilities; any process running as the pollen daemon can simply execute systemctl to gain root. No EPSS data is available and the flaw is not yet listed in CISA KEV, but the lack of restrictions means the risk remains significant for devices in use.
OpenCVE Enrichment