Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
ecovacs vulnerabilities and exploits
(subscribe to this query)
7.4
CVSSv3
CVE-2024-52330
ECOVACS lawnmowers and vacuums do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic, possibly modifying firmware updates.
Ecovacs Deebot X5 Pro Plus
Ecovacs Deebot X5 Pro
Ecovacs Deebot X2s
Ecovacs Deebot X2 Omni
Ecovacs Deebot X1 Turbo
Ecovacs Deebot X1
Ecovacs Deebot X1s Pro
Ecovacs Deebot X1e Omni
Ecovacs Deebot T10 Plus
Ecovacs Deebot T10 Omni
Ecovacs Deebot X5 Pro Ultra
Ecovacs Mate X
9.6
CVSSv3
CVE-2024-52325
ECOVACS robot lawnmowers and vacuums are vulnerable to command injection via SetNetPin() over an unauthenticated BLE connection.
Ecovacs Goat G1
Ecovacs Goat G1-800
Ecovacs Deebot X2s
Ecovacs Deebot X5 Pro
Ecovacs Deebot X5 Pro Plus
Ecovacs Deebot T30 Omni
Ecovacs Deebot T30s
Ecovacs Goat G1-2000
Ecovacs Goat Gx-600
Ecovacs Deebot X2 Omni
Ecovacs Deebot X2 Combo
Ecovacs Deebot X5 Pro Ultra
6.5
CVSSv3
CVE-2024-52327
The cloud service used by ECOVACS robot lawnmowers and vacuums allows authenticated malicious users to bypass the PIN entry required to access the live video feed.
Ecovacs Ecovacs Home
Ecovacs Cloud Service
7.4
CVSSv3
CVE-2024-52329
ECOVACS HOME mobile app plugins for specific robots do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic and obtain authentication tokens.
Ecovacs Ecovacs Home
7.6
CVSSv3
CVE-2024-11147
ECOVACS robot lawnmowers and vacuums use a deterministic root password generated based on model and serial number. An attacker with shell access can login as root.
Ecovacs Unspecified Robots
3.3
CVSSv3
CVE-2024-12079
ECOVACS robot lawnmowers store the anti-theft PIN in cleartext on the device filesystem. An attacker can steal a lawnmower, read the PIN, and reset the anti-theft mechanism.
Ecovacs Unspecified Robots
6.3
CVSSv3
CVE-2024-12078
ECOVACS robot lawn mowers and vacuums use a shared, static secret key to encrypt BLE GATT messages. An unauthenticated attacker within BLE range can control any robot using the same key.
Ecovacs Unspecified Robots
2.3
CVSSv3
CVE-2024-52328
ECOVACS robot lawnmowers and vacuums insecurely store audio files used to indicate that the camera is on. An attacker with access to the /data filesystem can delete or modify warning files such that users may not be aware that the camera is on.
Ecovacs Unspecified Robots
7.5
CVSSv3
CVE-2024-52331
ECOVACS robot lawnmowers and vacuums use a deterministic symmetric key to decrypt firmware updates. An attacker can create and encrypt malicious firmware that will be successfully decrypted and installed by the robot.
Ecovacs Unspecified Robots
NA
CVE-2024-42911
ECOVACS Robotics Deebot T20 OMNI and T20e OMNI prior to 1.24.0 exists to contain a WiFi Remote Code Execution vulnerability.
Preferred Score:
CVSSv3
CVSSv2
CVSSv3
CVSSv4
EPSS
VMScore
Recommendations:
type confusion
unspecified
CVE-2025-24200
reflected XSS
panel
CVE-2024-12549
temporal technologies, inc.
CVE-2024-21971
CVE-2024-57777
CVE-2023-31122
CVE-2025-0909
winzip computing
unified secops platform
Home
/
Search Results
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started