Improper Certificate Validation in Tomofun Furbo Devices
CVE-2025-11633
What is CVE-2025-11633?
A security vulnerability has been discovered in the Tomofun Furbo 360 and Furbo Mini devices that impacts the functionality of the HTTP Traffic Handler component. This issue pertains to improper validation of SSL/TLS certificates, potentially allowing attackers to execute remote operations. Exploitation requires advanced techniques, posing a challenge for attackers. The vulnerability affects specific firmware versions: Furbo 360 up to FB0035_FW_036 and Furbo Mini up to MC0020_FW_074. Despite early contact attempts, the vendor has not responded regarding this disclosure, leaving users at risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Furbo 360
Furbo Mini
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
