Impact
The Reachy Mini Bluetooth service requires a PIN exchange before accepting commands, but its authentication state is stored in a single shared flag. The write handler ignores the device identity passed via options, so once any device authenticates the flag is set and all nearby devices can send commands. This race condition allows an attacker within Bluetooth range to obtain an authenticated session without knowing the PIN, enabling arbitrary command execution over Bluetooth. The flaw directly leads to unauthorized control of the robot.
Affected Systems
The vendor affected is Pollen Robotics, product Reachy Mini. No specific firmware or version information is provided in the CVE record, so any running instance of Reachy Mini may be vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity. The EPSS score is not available, but the flaw requires only local Bluetooth proximity and no brute‑force effort, making the attack straightforward when an authorized user is present. The vulnerability is not listed in the CISA KEV catalog, so no widespread exploitation is currently documented.
OpenCVE Enrichment