Bluetooth Low Energy Vulnerability in Tomofun Furbo 360 and Furbo Mini
CVE-2025-11640
2.3LOW
What is CVE-2025-11640?
A vulnerability has been identified in the Tomofun Furbo 360 and Furbo Mini products, specifically within the Bluetooth Low Energy component. This flaw allows sensitive information to be transmitted in cleartext, potentially exposing it to interception by unauthorized entities. To exploit this vulnerability, an attacker must have access to the local network, making the attack complex and challenging to execute. The affected firmware versions include Furbo 360 up to version FB0035_FW_036 and Furbo Mini up to version MC0020_FW_074. Despite early disclosure to the vendor, there has been no response regarding the issue.
Affected Version(s)
Furbo 360
Furbo Mini