CVE-2025-10772: huggingface LeRobot ZeroMQ Socket lekiwi_remote.py missing authentication
A vulnerability was identified in huggingface LeRobot up to 0.3.3. Affected by this vulnerability is an unknown functionality of the file lerobot/common/robotdevices/robots/lekiwiremote.py of the component ZeroMQ Socket Handler. The manipulation leads to missing authentication. The attack can only be initiated within the local network. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10772?
CVE-2025-10772 has been categorized as a high-severity vulnerability due to its potential to allow unauthorized access.
How do I fix CVE-2025-10772?
To mitigate CVE-2025-10772, upgrade huggingface LeRobot to version 0.3.4 or later.
What types of attacks can CVE-2025-10772 enable?
CVE-2025-10772 can enable attacks such as unauthorized access to sensitive data and system manipulation due to missing authentication.
Which versions of huggingface LeRobot are affected by CVE-2025-10772?
Versions of huggingface LeRobot up to and including 0.3.3 are affected by CVE-2025-10772.
What component is affected by CVE-2025-10772?
CVE-2025-10772 affects the ZeroMQ Socket Handler within the file lerobot/common/robot_devices/robots/lekiwi_remote.py.