ECOVACS lawnmowers and vacuums do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic, possibly modifying firmware updates.
References
Link | Resource |
---|---|
https://dontvacuum.me/talks/37c3-2023/37c3-vacuuming-and-mowing.pdf | Exploit Third Party Advisory |
https://dontvacuum.me/talks/HITCON2024/HITCON-CMT-2024_Ecovacs.pdf | Exploit Third Party Advisory |
https://www.ecovacs.com/global/userhelp/dsa20241217001 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
AND |
|
Configuration 10 (hide)
AND |
|
Configuration 11 (hide)
AND |
|
Configuration 12 (hide)
AND |
|
Configuration 13 (hide)
AND |
|
Configuration 14 (hide)
AND |
|
Configuration 15 (hide)
AND |
|
Configuration 16 (hide)
AND |
|
Configuration 17 (hide)
AND |
|
Configuration 18 (hide)
AND |
|
Configuration 19 (hide)
AND |
|
Configuration 20 (hide)
AND |
|
History
23 Sep 2025, 17:48
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
CPE | cpe:2.3:h:ecovacs:deebot_x1:-:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x1e_omni_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x5_pro_plus:-:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:mate_x_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_t10_turbo_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x1s_pro_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_t10_omni_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x1_turbo_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x1_plus:-:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x5_pro_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x5_pro_ultra_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x1_plus_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x1_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x2_pro:-:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x1s_pro_plus_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x1_omni:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x5_pro:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:mate_x:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x1_pro_omni:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_t10_plus:-:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_t10_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x2_combo:-:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x2_combo_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x2s_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x2s:-:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x5_pro_plus_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x5_pro_ultra:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x1s_pro:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_t10_turbo:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x1_turbo:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x2_omni:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x1s_pro_plus:-:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x2_pro_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x1_pro_omni_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_t10:-:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x1_omni_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x1e_omni:-:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x2_omni_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_t10_plus_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_t10_omni:-:*:*:*:*:*:*:* |
|
References | () https://dontvacuum.me/talks/37c3-2023/37c3-vacuuming-and-mowing.pdf - Exploit, Third Party Advisory | |
References | () https://dontvacuum.me/talks/HITCON2024/HITCON-CMT-2024_Ecovacs.pdf - Exploit, Third Party Advisory | |
References | () https://www.ecovacs.com/global/userhelp/dsa20241217001 - Vendor Advisory | |
First Time |
Ecovacs deebot X1 Turbo Firmware
Ecovacs deebot X5 Pro Ecovacs deebot X5 Pro Firmware Ecovacs deebot X1 Pro Omni Firmware Ecovacs deebot X1s Pro Firmware Ecovacs deebot X1e Omni Ecovacs deebot X1s Pro Ecovacs deebot X1 Plus Ecovacs deebot X1 Pro Omni Ecovacs Ecovacs deebot T10 Turbo Ecovacs deebot X1 Ecovacs deebot X2 Pro Ecovacs deebot X1s Pro Plus Ecovacs deebot X1e Omni Firmware Ecovacs deebot X1s Pro Plus Firmware Ecovacs deebot X2 Omni Ecovacs deebot T10 Ecovacs deebot X2 Combo Ecovacs deebot X2s Firmware Ecovacs deebot X1 Plus Firmware Ecovacs deebot X1 Turbo Ecovacs deebot T10 Omni Ecovacs deebot X5 Pro Plus Ecovacs deebot T10 Omni Firmware Ecovacs deebot T10 Turbo Firmware Ecovacs deebot X1 Omni Firmware Ecovacs mate X Ecovacs deebot X1 Firmware Ecovacs deebot X5 Pro Ultra Firmware Ecovacs deebot X2 Combo Firmware Ecovacs deebot T10 Plus Firmware Ecovacs mate X Firmware Ecovacs deebot X2s Ecovacs deebot X2 Omni Firmware Ecovacs deebot X2 Pro Firmware Ecovacs deebot T10 Plus Ecovacs deebot X5 Pro Ultra Ecovacs deebot X5 Pro Plus Firmware Ecovacs deebot X1 Omni Ecovacs deebot T10 Firmware |
23 Jan 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-01-23 17:15
Updated : 2025-09-23 17:48
NVD link : CVE-2024-52330
Mitre link : CVE-2024-52330
CVE.ORG link : CVE-2024-52330
JSON object : View
Products Affected
ecovacs
- deebot_x2_combo_firmware
- deebot_x2_combo
- deebot_x1_pro_omni_firmware
- deebot_x2_pro_firmware
- deebot_x1_turbo
- deebot_x2_pro
- deebot_x1s_pro_plus_firmware
- deebot_x1_pro_omni
- deebot_x2s_firmware
- deebot_t10_omni
- mate_x_firmware
- deebot_t10
- deebot_t10_turbo
- deebot_x1_turbo_firmware
- deebot_x2s
- deebot_x1_plus
- deebot_t10_firmware
- mate_x
- deebot_x5_pro_plus_firmware
- deebot_x1
- deebot_x1_omni_firmware
- deebot_x1e_omni_firmware
- deebot_x1_omni
- deebot_x1_plus_firmware
- deebot_x1s_pro_plus
- deebot_x5_pro_firmware
- deebot_t10_turbo_firmware
- deebot_x5_pro_ultra_firmware
- deebot_x5_pro_plus
- deebot_x1e_omni
- deebot_x1s_pro_firmware
- deebot_t10_plus_firmware
- deebot_x5_pro
- deebot_x1s_pro
- deebot_t10_plus
- deebot_t10_omni_firmware
- deebot_x2_omni_firmware
- deebot_x1_firmware
- deebot_x2_omni
- deebot_x5_pro_ultra
CWE
CWE-295
Improper Certificate Validation