Bluetooth Low Energy Vulnerability in Tomofun Furbo 360 and Furbo Mini
CVE-2025-11640

2.3LOW

Key Information:

Vendor

Tomofun

Vendor
CVE Published:
12 October 2025

What is CVE-2025-11640?

A vulnerability has been identified in the Tomofun Furbo 360 and Furbo Mini products, specifically within the Bluetooth Low Energy component. This flaw allows sensitive information to be transmitted in cleartext, potentially exposing it to interception by unauthorized entities. To exploit this vulnerability, an attacker must have access to the local network, making the attack complex and challenging to execute. The affected firmware versions include Furbo 360 up to version FB0035_FW_036 and Furbo Mini up to version MC0020_FW_074. Despite early disclosure to the vendor, there has been no response regarding the issue.

Affected Version(s)

Furbo 360

Furbo Mini

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

jTag Labs (VulDB User)
.