Security Flaw in Tomofun Furbo 360 and Mini Devices
CVE-2025-11643
What is CVE-2025-11643?
A security flaw has been identified in the Tomofun Furbo 360 and Furbo Mini, specifically affecting the MQTT Client Certificate functionality. This vulnerability results in the exposure of hard-coded credentials, which can be exploited by an attacker remotely. The issue resides within the file /squashfs-root/furbo_img, and successful exploitation allows unauthorized access to sensitive information. Despite attempts to inform the vendor regarding this security concern, there has been no response to date. Users of affected firmware versions should take immediate action to secure their devices.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Furbo 360
Furbo Mini
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
