Access Control Vulnerability in Tomofun Furbo 360 and Furbo Mini
CVE-2025-11641

1LOW

Key Information:

Vendor

Tomofun

Vendor
CVE Published:
12 October 2025

What is CVE-2025-11641?

A vulnerability has been identified in the Tomofun Furbo 360 and Furbo Mini involving the Trial Restriction Handler, leading to improper access control. This vulnerability can be exploited on the physical device, presenting a significant risk, particularly given the high complexity of the attack. Affected firmware versions include Furbo 360 up to FB0035_FW_036 and Furbo Mini up to MC0020_FW_074. Despite attempts to inform the vendor, no response was received regarding this issue.

Affected Version(s)

Furbo 360

Furbo Mini

References

CVSS V4

Score:
1
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Physical
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

jTag Labs (VulDB User)
.
CVE-2025-11641 : Access Control Vulnerability in Tomofun Furbo 360 and Furbo Mini