CVE-2024-52331

ECOVACS robot lawnmowers and vacuums use a deterministic symmetric key to decrypt firmware updates. An attacker can create and encrypt malicious firmware that will be successfully decrypted and installed by the robot.
Configurations

No configuration.

History

23 Jan 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-23 17:15

Updated : 2025-01-23 17:15


NVD link : CVE-2024-52331

Mitre link : CVE-2024-52331

CVE.ORG link : CVE-2024-52331


JSON object : View

Products Affected

No product.

CWE
CWE-494

Download of Code Without Integrity Check

CWE-1391

Use of Weak Credentials