CVE-2025-10772 | huggingface LeRobot up to 0.3.3 ZeroMQ Socket lekiwi_remote.py missing authentication

SecurityVulns

A vulnerability was found in huggingface LeRobot up to 0.3.3. It has been classified as critical. Affected by this vulnerability is an unknown functionality of the file lerobot/common/robot_devices/robots/lekiwi_remote.py of the component ZeroMQ Socket Handler. The manipulation leads to missing authentication.

This vulnerability is uniquely identified as CVE-2025-10772. The attack can only be initiated within the local network. No exploit exists.

The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More