CyberRota Analysis
AI-GeneratedThe Reachy Mini ISO for Wireless prior to version 0.2.4 contains a critical local privilege escalation vulnerability due to an overly permissive sudoers entry that allows the pollen daemon user to execute systemctl commands without restrictions. This flaw enables any process running as pollen to gain full root access on the device with minimal effort. Organizations using this OS image, particularly those deploying Reachy Mini Wireless robots, should prioritize upgrading to version 0.2.4 to mitigate the risk of unauthorized access.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Reachy Mini ISO for Wireless contains the necessary files to build a custom Raspberry Pi OS image for the Reachy Mini Wireless robot, using pi-gen. Prior to version 0.2.4, the Reachy Mini Wireless OS image shipped with an overly broad sudoers entry granting the pollen daemon user (uid 1000) passwordless sudo access to /usr/bin/systemctl with no subcommand or argument restriction. This is a local privilege escalation (LPE). Any process running as pollen can obtain full root (uid 0) on the device in three commands, with no additional vulnerability required and no user interaction. This issue has been patched in version 0.2.4.