CVE-2025-10772 | huggingface LeRobot up to 0.3.3 ZeroMQ Socket lekiwi_remote.py missing authentication (EUVD-2025-30385 / CNNVD-202509-3627)
A vulnerability was found in huggingface LeRobot up to 0.3.3. It has been classified as critical. Affected by this vulnerability is an unknown functionality of the file lerobot/common/robot_devices/robots/lekiwi_remote.py of the component ZeroMQ Socket Handler. The manipulation leads to missing authentication.
This vulnerability is uniquely identified as CVE-2025-10772. The attack can only be initiated within the local network. No exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.