CVE-2026-8153
CVSS 9.8 CRITICAL: oS command injection in Dashboard Server interface in Universal Robots PolyScope versions prior to 5.25.1 allows… EPSS 3% (87º percentile).
Vulnerabilità ed exploit · Attacco IoT / OT
Si tratta di esecuzione di codice senza autenticazione sul robot controller stesso, non solo di un altro servizio web esposto. Se Polyscope 5 è compromesso, un attaccante può influenzare il comportamento del robot e l’integrità del firmware, e una correzione solo di rete potrebbe non annullare le modifiche già apportate sulla macchina.
3 fonti · 20 mag
CVSS 9.8 CRITICAL: oS command injection in Dashboard Server interface in Universal Robots PolyScope versions prior to 5.25.1 allows… EPSS 3% (87º percentile).
Dark Reading
Patch Now: Critical Flaw in OT Robot OS Gives Attackers Control
An attacker can exploit the command injection flaw to gain remote access to robotic systems, causing significant disruption to the environment.
originaleSecurityWeek
Critical Vulnerability Exposes Industrial Robot Fleets to Hacking
The vulnerability, CVE-2026-8153, affects Universal Robots PolyScope 5 and it can be exploited for OS command injection.
originaleCISA Advisories
Universal Robots Polyscope 5 | CISA
Universal Robots Polyscope 5 Summary Successful exploitation of these vulnerabilities could allow an attacker to bypass authentication and execute code.
originalePart of the PlainSec briefing for 2026-05-20
Every edition of this story: Vulnerabilità del Robot Controller Può Alterare il Comportamento del Processo Fisico