f2.png

This post describes three vulnerabilities in the Double Robotics Telepresence Robot ecosystem related to improper authentication, session fixation, and weak Bluetooth pairing. We would like to thank Double Robotics for their prompt acknowledgement of the vulnerabilities, and in addressing the ones that they considered serious. Two of the three vulnerabilities were patched via updates to Double Robotics servers on Mon, Jan 16, 2017.

https://community.rapid7.com/community/infosec/blog/2017/03/13/r7-2017-01-multiple-vulnerabilities-in-double-robotics-telepresence-robot