← Back to CVE search

CVE-2026-16081

Sipeed PicoClaw

Description

A vulnerability was determined in Sipeed PicoClaw up to 0.2.9. The affected element is an unknown function of the file web/backend/api/auth.go. Executing a manipulation can lead to cross-site request forgery. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. This patch is called 4b0229351678f479429b8d8b19207757266f246b. Applying a patch is advised to resolve this issue.

CVSS 4.3EPSS 0.166%Risk 0.44
View source
Published
2026-07-18 08:16:35
Affected versions
<=0.2.9
Type
Firmware
Last modified
2026-07-20 15:16:35
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N