CVE Alert: CVE-2025-11649 – Tomofun – Furbo 360

CVE-2025-11649

HIGHNo exploitation known

A vulnerability was found in Tomofun Furbo 360 and Furbo Mini. The affected element is an unknown function of the component Root Account Handler. Performing manipulation results in use of hard-coded password. The attack must be initiated from a local position. The attack is considered to have high complexity. The exploitability is described as difficult. The exploit has been made public and could be used. The firmware versions determined to be affected are Furbo 360 up to FB0035_FW_036 and Furbo Mini up to MC0020_FW_074. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS v3.1 (7)
Vendor
Tomofun, Tomofun
Product
Furbo 360, Furbo Mini
Versions
n/a | n/a
CWE
CWE-259, Use of Hard-coded Password
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R
Published
2025-10-12T22:32:05.850Z
Updated
2025-10-12T22:32:05.850Z

AI Summary Analysis

Risk verdict

Why this matters

Most likely attack path

Who is most exposed

Detection ideas

  • Unauthorised root login events from the device.
  • Repeated authentication attempts using default/root credentials.
  • Unusual processes named “Root Account Handler” or similar.
  • Anomalous outbound traffic from the device to unfamiliar endpoints.
  • Firmware versions showing signs of known vulnerable builds.

Mitigation and prioritisation

  • Apply vendor firmware updates as soon as available; monitor advisories for fixed releases.
  • Remove or rotate hard-coded credentials; enforce credential management where feasible.
  • Restrict local access to the device; disable unnecessary admin interfaces; implement network segmentation.
  • Monitor for root-level activity and establish baseline process/network profiles for rapid alerting.
  • Plan change management for a firmware upgrade window and verify post-patch configurations.

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on “Patreon” or “Buy Me A Coffee” using the buttons below

To keep up to date follow us on the below channels.