{"api_version":"1","generated_at":"2026-07-23T04:27:23+00:00","cve":"CVE-2020-16167","urls":{"html":"https://cve.report/CVE-2020-16167","api":"https://cve.report/api/cve/CVE-2020-16167.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-16167","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-16167"},"summary":{"title":"CVE-2020-16167","description":"Missing Authentication for Critical Function in temi Robox OS prior to 120, temi Android app up to 1.3.7931 allows remote attackers to receive and answer calls intended for another temi user. Answering the call this way grants motor control of the temi in addition to audio/video via unspecified vectors.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2020-08-07 20:15:00","updated_at":"2020-09-02 19:15:00"},"problem_types":["CWE-306"],"metrics":[],"references":[{"url":"https://www.robotemi.com/software-updates/","name":"https://www.robotemi.com/software-updates/","refsource":"MISC","tags":["Vendor Advisory"],"title":"Software Updates - temi robot","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.mcafee.com/blogs/other-blogs/mcafee-labs/call-an-exorcist-my-robots-possessed/","name":"https://www.mcafee.com/blogs/other-blogs/mcafee-labs/call-an-exorcist-my-robots-possessed/","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"Call an Exorcist! My Robot’s Possessed! | McAfee Blogs","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-16167","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-16167","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"16167","vulnerable":"1","versionEndIncluding":"13146","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"robotemi","cpe5":"launcher_os","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2020-16167","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Missing Authentication for Critical Function in temi Robox OS prior to 120, temi Android app up to 1.3.7931 allows remote attackers to receive and answer calls intended for another temi user. Answering the call this way grants motor control of the temi in addition to audio/video via unspecified vectors."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://www.robotemi.com/software-updates/","refsource":"MISC","name":"https://www.robotemi.com/software-updates/"},{"refsource":"MISC","name":"https://www.mcafee.com/blogs/other-blogs/mcafee-labs/call-an-exorcist-my-robots-possessed/","url":"https://www.mcafee.com/blogs/other-blogs/mcafee-labs/call-an-exorcist-my-robots-possessed/"}]}},"nvd":{"publishedDate":"2020-08-07 20:15:00","lastModifiedDate":"2020-09-02 19:15:00","problem_types":["CWE-306"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":9.1,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.2},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":6.4},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:robotemi:launcher_os:*:*:*:*:*:*:*:*","versionStartIncluding":"11969","versionEndIncluding":"13146","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"16167","Ordinal":"177575","Title":"CVE-2020-16167","CVE":"CVE-2020-16167","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"16167","Ordinal":"1","NoteData":"Missing Authentication for Critical Function in temi Robox OS prior to 120, temi Android app up to 1.3.7931 allows remote attackers to receive and answer calls intended for another temi user. Answering the call this way grants motor control of the temi in addition to audio/video via unspecified vectors.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"16167","Ordinal":"2","NoteData":"2020-08-07","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"16167","Ordinal":"3","NoteData":"2020-09-02","Type":"Other","Title":"Modified"}]}}}