Executive brief
Universal Robots Polyscope 5, the operating software for industrial collaborative robots, contains a critical security flaw. An attacker can bypass security controls to take full control of the robot's operating system without needing a password. This could lead to unauthorized movement of the robot, production downtime, or the theft of sensitive manufacturing data.
Technical details
An OS command injection vulnerability (CWE-78) exists in the Dashboard Server interface of Universal Robots PolyScope 5. The flaw is caused by improper neutralization of special elements in user-supplied input, allowing a remote, unauthenticated attacker to craft malicious commands. Successful exploitation enables the execution of arbitrary code with the privileges of the robot's operating system. The vulnerability affects all versions prior to 5.25.1 and can be exploited over the network without user interaction. Universal Robots has released version 5.25.1 to address this issue.
Affected products
- Universal Robots Polyscope 5 < 5.25.1
Timeline
- 2026-05-14: disclosed
- 2026-05-14: advisory: ICSA-26-134-17 published by CISA
- 2026-05-14: patched: Fixed in version 5.25.1