Researcher who found McDonald's free-food hack turns her attention to Chinese restaurant robots
ID: 838abf61-f5bb-5f4d-9fd2-9e3c1614f4da
STIX ID: report--838abf61-f5bb-5f4d-9fd2-9e3c1614f4da
Feed Name: The Register (Security)
Threat Score
A researcher found a critical administrative/authentication weakness in Pudu Robotics' backend that allowed anyone with a valid auth token — obtainable via XSS or account signup — to control and redirect service robots, reset orders, move and rename units, and potentially disrupt restaurant operations or exfiltrate IP; Pudu initially ignored the report but subsequently fixed the issue, awarded a $10,000 bounty, and created a security response center.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
