CVE-2025-10772 - Huggingface LeRobot ZeroMQ Socket Handler Authentication Bypass

CVE ID : CVE-2025-10772
Published : Sept. 22, 2025, 1:08 a.m. | 54 minutes ago
Description : A vulnerability was identified in huggingface LeRobot up to 0.3.3. Affected by this vulnerability is an unknown functionality of the file lerobot/common/robot_devices/robots/lekiwi_remote.py of the component ZeroMQ Socket Handler. The manipulation leads to missing authentication. The attack can only be initiated within the local network. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

from Latest Vulnerabilities https://ift.tt/CPAWuOY
via IFTTT

Post a Comment

Please Select Embedded Mode To Show The Comment System.*

Previous Post Next Post