HOMEVULNERABILITIESCVE-2018-20785
HIGH

CVE-2018-20785

NVD-CWE-noinfoPublished: February 23, 2019· Updated: Jun 17, 2026

7.4
CVSS v3.1

Official Description

Secure boot bypass and memory extraction can be achieved on Neato Botvac Connected 2.2.0 devices. During startup, the AM335x secure boot feature decrypts and executes firmware. Secure boot can be bypassed by starting with certain commands to the USB serial port. Although a power cycle occurs, this does not completely reset the chip: memory contents are still in place. Also, it restarts into a boot menu that enables XMODEM upload and execution of an unsigned QNX IFS system image, thereby completing the bypass of secure boot. Moreover, the attacker can craft custom IFS data and write it to unused memory to extract all memory contents that had previously been present. This includes the original firmware and sensitive information such as Wi-Fi credentials.

NVD Source

Technical Analysis

CVE-2018-20785 requires local access, meaning attackers must already have a foothold on the target system.

The vulnerability requires no privileges and no user interaction, making it a prime target for automated exploitation campaigns and worm-like propagation.

A successful exploit results in complete confidentiality breach (data exposure), full integrity compromise (data manipulation), availability disruption (denial of service), with a CVSS base score of 7.4.

CVSS v3.1 Vector Breakdown

Exploitability
Attack VectorLocal
Attack ComplexityHigh
Privileges Req.None
User InteractionNone
ScopeUnchanged
Impact
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Vendors & Products

neatorobotics14 product(s)
botvac d4 connected firmwarebotvac d4 connectedbotvac d6 connected firmwarebotvac d6 connectedbotvac d5 connected firmwarebotvac d5 connectedbotvac d7 connected firmwarebotvac d7 connectedbotvac d3 connected firmwarebotvac d3 connectedbotvac d3 pro connected firmwarebotvac d3 pro connected+2
Source: NVD CPE · 14 total CPE entries

Exploit & PoC Resources

NO KNOWN EXPLOITNo public exploit confirmed at this time
External links open in a new tab. Always verify in a controlled environment before use.

Official Patches & Advisories

All References (2)

Quick Facts

CVE IDCVE-2018-20785
CVSS Score7.4 / 10
SeverityHIGH
CISA KEVNo
Affected1 vendor(s)
PublishedFeb 23, 2019

Related CVEs (NVD-CWE-noinfo)

Recommended Actions

  • Apply vendor patches immediately
  • Monitor CVE-2018-20785 in threat intel feeds
  • Review IDS/IPS signatures for exploitation attempts
Data sourced from NVD (NIST), CISA KEV, and EPSS (FIRST). Analysis generated by CTIWatch. CVE data is provided under the NVD usage policy.