{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2025-11641","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2025-10-11T18:32:47.228Z","datePublished":"2025-10-12T18:32:05.050Z","dateUpdated":"2025-10-17T05:49:10.328Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2025-10-17T05:49:10.328Z"},"title":"Tomofun Furbo 360/Furbo Mini Trial Restriction access control","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-284","lang":"en","description":"Improper Access Controls"}]},{"descriptions":[{"type":"CWE","cweId":"CWE-266","lang":"en","description":"Incorrect Privilege Assignment"}]}],"affected":[{"vendor":"Tomofun","product":"Furbo 360","versions":[{"version":"n/a","status":"affected"}],"modules":["Trial Restriction Handler"]},{"vendor":"Tomofun","product":"Furbo Mini","versions":[{"version":"n/a","status":"affected"}],"modules":["Trial Restriction Handler"]}],"descriptions":[{"lang":"en","value":"A vulnerability was determined in Tomofun Furbo 360 and Furbo Mini. This impacts an unknown function of the component Trial Restriction Handler. This manipulation causes improper access controls. It is feasible to perform the attack on the physical device. The attack is considered to have high complexity. The exploitability is said to be difficult. The firmware versions determined to be affected are Furbo 360 up to FB0035_FW_036 and Furbo Mini up to MC0020_FW_074. The vendor was contacted early about this disclosure but did not respond in any way."},{"lang":"de","value":"Eine Schwachstelle wurde in Tomofun Furbo 360 and Furbo Mini gefunden. Dies betrifft einen unbekannten Teil der Komponente Trial Restriction Handler. Durch Manipulation mit unbekannten Daten kann eine improper access controls-Schwachstelle ausgenutzt werden. Der Angriff auf das physische Gerät ist möglich. Ein Angriff erfordert eine vergleichsweise hohe Komplexität. Die Ausnutzbarkeit gilt als schwierig."}],"metrics":[{"cvssV4_0":{"version":"4.0","baseScore":1,"vectorString":"CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X","baseSeverity":"LOW"}},{"cvssV3_1":{"version":"3.1","baseScore":3.9,"vectorString":"CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:X","baseSeverity":"LOW"}},{"cvssV3_0":{"version":"3.0","baseScore":3.9,"vectorString":"CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:X","baseSeverity":"LOW"}},{"cvssV2_0":{"version":"2.0","baseScore":3.7,"vectorString":"AV:L/AC:H/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:ND"}}],"timeline":[{"time":"2025-05-15T20:00:00.000Z","lang":"en","value":"Vulnerability found"},{"time":"2025-06-21T23:00:00.000Z","lang":"en","value":"Vendor informed"},{"time":"2025-07-03T04:30:00.000Z","lang":"en","value":"Vendor acknowledged"},{"time":"2025-10-11T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2025-10-11T02:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2025-10-17T07:54:06.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"Calvin Star (Software Secured)","type":"finder"},{"lang":"en","value":"Julian B (Software Secured)","type":"finder"},{"lang":"en","value":"jTag Labs (VulDB User)","type":"reporter"},{"lang":"en","value":"jTag Labs (VulDB User)","type":"analyst"}],"references":[{"url":"https://vuldb.com/?id.328052","name":"VDB-328052 | Tomofun Furbo 360/Furbo Mini Trial Restriction access control","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/?ctiid.328052","name":"VDB-328052 | CTI Indicators (IOB, IOC, TTP)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/?submit.661379","name":"Submit #661379 | Tomofun Furbo 360, Furbo Mini Furbo 360 (≤ FB0035_FW_036), Furbo Mini (≤ MC0020_FW_074) Application Logic Bypass","tags":["third-party-advisory"]}]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-10-14T14:59:44.158815Z","id":"CVE-2025-11641","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-10-14T14:59:51.878Z"}}]}}