{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2025-11637","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2025-10-11T18:32:31.274Z","datePublished":"2025-10-12T16:32:06.156Z","dateUpdated":"2025-10-16T05:39:49.182Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2025-10-16T05:39:49.182Z"},"title":"Tomofun Furbo 360 Audio race condition","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-362","lang":"en","description":"Race Condition"}]}],"affected":[{"vendor":"Tomofun","product":"Furbo 360","versions":[{"version":"FB0035_FW_036","status":"affected"}],"modules":["Audio Handler"]}],"descriptions":[{"lang":"en","value":"A vulnerability was detected in Tomofun Furbo 360 up to FB0035_FW_036. Impacted is an unknown function of the component Audio Handler. Performing manipulation results in race condition. The attack is possible to be carried out remotely. The vendor was contacted early about this disclosure but did not respond in any way."},{"lang":"de","value":"Eine Schwachstelle wurde in Tomofun Furbo 360 up to FB0035_FW_036 gefunden. Es ist betroffen eine unbekannte Funktion der Komponente Audio Handler. Dank der Manipulation mit unbekannten Daten kann eine race condition-Schwachstelle ausgenutzt werden. Es ist möglich, den Angriff aus der Ferne durchzuführen."}],"metrics":[{"cvssV4_0":{"version":"4.0","baseScore":5.3,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X","baseSeverity":"MEDIUM"}},{"cvssV3_1":{"version":"3.1","baseScore":4.3,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:X","baseSeverity":"MEDIUM"}},{"cvssV3_0":{"version":"3.0","baseScore":4.3,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:X","baseSeverity":"MEDIUM"}},{"cvssV2_0":{"version":"2.0","baseScore":4,"vectorString":"AV:N/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:ND/RC:ND"}}],"timeline":[{"time":"2025-05-15T20:00:00.000Z","lang":"en","value":"Vulnerability found"},{"time":"2025-06-21T23:00:00.000Z","lang":"en","value":"Vendor informed"},{"time":"2025-07-03T04:30:00.000Z","lang":"en","value":"Vendor acknowledged"},{"time":"2025-10-11T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2025-10-11T02:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2025-10-16T07:44:45.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"Calvin Star (Software Secured)","type":"finder"},{"lang":"en","value":"Julian B (Software Secured)","type":"finder"},{"lang":"en","value":"jTag Labs (VulDB User)","type":"reporter"},{"lang":"en","value":"jTag Labs (VulDB User)","type":"analyst"}],"references":[{"url":"https://vuldb.com/?id.328048","name":"VDB-328048 | Tomofun Furbo 360 Audio race condition","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/?ctiid.328048","name":"VDB-328048 | CTI Indicators (IOB, IOC)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/?submit.661362","name":"Submit #661362 | Tomofun Furbo 360 ≤ FB0035_FW_036 Race Condition","tags":["third-party-advisory"]}]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-10-14T15:06:38.667217Z","id":"CVE-2025-11637","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-10-14T15:06:45.540Z"}}]}}