4.3
CVSSv2

CVE-2019-12820

Published: 19/07/2019 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.6 | Impact Score: 3.4 | Exploitability Score: 2.2
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

A vulnerability was found in the app 2.0 of the Shenzhen Jisiwei i3 robot vacuum cleaner. Actions performed on the app such as changing a password, and personal information it communicates with the server, use unencrypted HTTP. As an example, while logging in through the app to a Jisiwei account, the login request is being sent in cleartext. The vulnerability exists in both the Android and iOS version of the app. An attacker could exploit this by using an MiTM attack on the local network to obtain someone's login credentials, which gives them full access to the robot vacuum cleaner.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jisiwei i3_firmware 2.0

Github Repositories

This is resources and documentation needed for recreating the hack for the JISIWEI Vacuum Cleaner Robot owned by the NSE Cyber Security Lab at KTH EECS.

JISIWEI Vacuum Cleaner Robot Demo Created: 2020-06-29 Revised: 2020-07-08 This project consists of resources and documentation needed for re-creating and to demo the hack for the JISIWEI Vacuum Cleaner Robot at the NSE Cyber Security Lab This demo will be based upon the HTTP vulnerability found in CVE-2019-12820 Tools Used Android Smartphone, with the JISIWEI application ins