'Security of your network is essential to security of your robot': Industrial robots targeted by malware,…

https://cdn.mos.cms.futurecdn.net/4DKiUF32YY5BX96h6fscGL-2560-80.jpg
  • Attackers can remotely execute commands on vulnerable industrial robots without requiring authentication
  • Outdated factory robots may expose entire manufacturing networks to devastating cyberattacks today
  • Poor network segmentation could allow compromised workstations to hijack nearby collaborative robots

A critical command injection vulnerability has been discovered in Universal Robots PolyScope 5, the operating system whucg powers the company's collaborative robots.

The flaw, tracked as CVE-2026-8153, carries a CVSS score of 9.8 and affects all software versions prior to PolyScope 5.25.1.

An unauthenticated attacker who can reach the Dashboard Server network port can craft commands that execute directly on the robot's underlying operating system.

Command injection vulnerability actually works

This vulnerability could lead to complete compromise of the robot controller, affecting the confidentiality, integrity, and availability of the entire system

The Dashboard Server accepts user-controlled input and passes it to the operating system without properly neutralizing special command elements.

This oversight allows an...

Copyright of this story solely belongs to techradar.com. To see the full text click HERE

Read more