CVE-2026-8153
CVSS 9.8 CRITICAL: oS command injection in Dashboard Server interface in Universal Robots PolyScope versions prior to 5.25.1 allows… EPSS 3% (87º percentile).
Vulnerabilità · 132 giorni fa
Si tratta di esecuzione di codice senza autenticazione sul robot controller stesso, non solo di un altro servizio web esposto. Se Polyscope 5 è compromesso, un attaccante può influenzare il comportamento del robot e l’integrità del firmware, e una correzione solo di rete potrebbe non annullare le modifiche già apportate sulla macchina.
CVSS 9.8 CRITICAL: oS command injection in Dashboard Server interface in Universal Robots PolyScope versions prior to 5.25.1 allows… EPSS 3% (87º percentile).
3 fonti che coprono questa storia
Patch Now: Critical Flaw in OT Robot OS Gives Attackers Control
An attacker can exploit the command injection flaw to gain remote access to robotic systems, causing significant disruption to the environment.
Critical Vulnerability Exposes Industrial Robot Fleets to Hacking
The vulnerability, CVE-2026-8153, affects Universal Robots PolyScope 5 and it can be exploited for OS command injection.
Universal Robots Polyscope 5 | CISA
Universal Robots Polyscope 5 Summary Successful exploitation of these vulnerabilities could allow an attacker to bypass authentication and execute code.
Part of the PlainSec briefing for 2026-05-21