Insecure Storage Vulnerability in Tomofun Furbo Devices
CVE-2025-11639
Key Information:
- Vendor
Tomofun
- Status
- Vendor
- CVE Published:
- 12 October 2025
Badges
What is CVE-2025-11639?
A vulnerability exists in the Tomofun Furbo 360 and Furbo Mini, related to the collect_logs.sh function within the Debug Log S3 Bucket Handler. This flaw allows for the insecure storage of sensitive information, posing a risk to user data security. The affected firmware versions are Furbo 360 up to FB0035_FW_036 and Furbo Mini up to MC0020_FW_074. Local access is required to exploit this issue. Despite early disclosure attempts, the vendor has not responded to outreach regarding this vulnerability.
Affected Version(s)
Furbo 360
Furbo Mini
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
