CVE-2024-52330

ECOVACS lawnmowers and vacuums do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic, possibly modifying firmware updates.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:ecovacs:deebot_x2_omni_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x2_omni:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:ecovacs:deebot_x2_combo_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x2_combo:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:ecovacs:deebot_x2s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x2s:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:ecovacs:deebot_x5_pro_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x5_pro:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:ecovacs:deebot_x5_pro_plus_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x5_pro_plus:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:ecovacs:deebot_x5_pro_ultra_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x5_pro_ultra:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:ecovacs:mate_x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:mate_x:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:ecovacs:deebot_x1_omni_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x1_omni:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:ecovacs:deebot_x1_turbo_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x1_turbo:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:ecovacs:deebot_x1_pro_omni_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x1_pro_omni:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:ecovacs:deebot_x1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x1:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:ecovacs:deebot_x1_plus_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x1_plus:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:ecovacs:deebot_x1s_pro_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x1s_pro:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:ecovacs:deebot_x1s_pro_plus_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x1s_pro_plus:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:ecovacs:deebot_x1e_omni_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x1e_omni:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:ecovacs:deebot_t10_turbo_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_t10_turbo:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:ecovacs:deebot_t10_plus_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_t10_plus:-:*:*:*:*:*:*:*

Configuration 18 (hide)

AND
cpe:2.3:o:ecovacs:deebot_t10_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_t10:-:*:*:*:*:*:*:*

Configuration 19 (hide)

AND
cpe:2.3:o:ecovacs:deebot_t10_omni_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_t10_omni:-:*:*:*:*:*:*:*

Configuration 20 (hide)

AND
cpe:2.3:o:ecovacs:deebot_x2_pro_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x2_pro:-:*:*:*:*:*:*:*

History

23 Sep 2025, 17:48

Type Values Removed Values Added
CPE cpe:2.3:o:ecovacs:deebot_x1e_omni_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x5_pro_ultra:-:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x1_omni:-:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_t10_turbo:-:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_x1s_pro_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_x5_pro_ultra_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_x2s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_x1_turbo_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_x1s_pro_plus_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x2s:-:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_x1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_t10_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_x2_omni_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_t10_omni:-:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x5_pro_plus:-:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x2_omni:-:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_x5_pro_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_t10_omni_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x2_combo:-:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:mate_x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_x1_pro_omni_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x1_pro_omni:-:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_x2_combo_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:mate_x:-:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x5_pro:-:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x1e_omni:-:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x1_plus:-:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x1_turbo:-:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x1:-:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_t10_turbo_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_x2_pro_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_x5_pro_plus_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_t10_plus_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_x1_plus_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_t10_plus:-:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_x1_omni_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_t10:-:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x2_pro:-:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x1s_pro:-:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x1s_pro_plus:-:*:*:*:*:*:*:*
Summary
  • (es) Las cortadoras de césped y las aspiradoras ECOVACS no validan correctamente los certificados TLS. Un atacante no autenticado puede leer o modificar el tráfico TLS, posiblemente modificando las actualizaciones de firmware.
First Time Ecovacs mate X Firmware
Ecovacs deebot X1s Pro Plus Firmware
Ecovacs deebot X1 Pro Omni
Ecovacs deebot X5 Pro Ultra Firmware
Ecovacs deebot X1 Omni
Ecovacs deebot X5 Pro
Ecovacs
Ecovacs deebot X2 Combo
Ecovacs deebot X1
Ecovacs deebot X2 Combo Firmware
Ecovacs deebot X5 Pro Firmware
Ecovacs deebot X2s Firmware
Ecovacs deebot T10 Turbo Firmware
Ecovacs mate X
Ecovacs deebot X1 Firmware
Ecovacs deebot T10
Ecovacs deebot X5 Pro Ultra
Ecovacs deebot T10 Plus Firmware
Ecovacs deebot X2 Omni Firmware
Ecovacs deebot X1 Pro Omni Firmware
Ecovacs deebot X5 Pro Plus Firmware
Ecovacs deebot X1 Plus
Ecovacs deebot X1 Turbo
Ecovacs deebot X1e Omni Firmware
Ecovacs deebot T10 Turbo
Ecovacs deebot X1s Pro Firmware
Ecovacs deebot X2 Pro
Ecovacs deebot X5 Pro Plus
Ecovacs deebot X2 Pro Firmware
Ecovacs deebot T10 Omni Firmware
Ecovacs deebot X1s Pro Plus
Ecovacs deebot T10 Firmware
Ecovacs deebot X2s
Ecovacs deebot T10 Plus
Ecovacs deebot X2 Omni
Ecovacs deebot X1 Omni Firmware
Ecovacs deebot X1e Omni
Ecovacs deebot X1 Plus Firmware
Ecovacs deebot X1 Turbo Firmware
Ecovacs deebot X1s Pro
Ecovacs deebot T10 Omni
References () https://dontvacuum.me/talks/37c3-2023/37c3-vacuuming-and-mowing.pdf - () https://dontvacuum.me/talks/37c3-2023/37c3-vacuuming-and-mowing.pdf - Exploit, Third Party Advisory
References () https://dontvacuum.me/talks/HITCON2024/HITCON-CMT-2024_Ecovacs.pdf - () https://dontvacuum.me/talks/HITCON2024/HITCON-CMT-2024_Ecovacs.pdf - Exploit, Third Party Advisory
References () https://www.ecovacs.com/global/userhelp/dsa20241217001 - () https://www.ecovacs.com/global/userhelp/dsa20241217001 - Vendor Advisory

23 Jan 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-23 17:15

Updated : 2025-09-23 17:48


NVD link : CVE-2024-52330

Mitre link : CVE-2024-52330

CVE.ORG link : CVE-2024-52330


JSON object : View

Products Affected

ecovacs

  • deebot_x5_pro_firmware
  • deebot_t10_plus
  • deebot_x1e_omni_firmware
  • deebot_x2_pro
  • deebot_x1_omni
  • deebot_x1s_pro
  • deebot_x1_pro_omni_firmware
  • deebot_x2_combo
  • deebot_x5_pro_ultra_firmware
  • deebot_x1_omni_firmware
  • deebot_x1
  • deebot_x2s
  • deebot_x1s_pro_plus_firmware
  • deebot_x5_pro_plus_firmware
  • deebot_t10_firmware
  • deebot_t10_omni_firmware
  • deebot_t10_turbo
  • deebot_t10_omni
  • deebot_x5_pro_ultra
  • deebot_t10_turbo_firmware
  • deebot_x2_combo_firmware
  • deebot_x2_omni
  • deebot_x1_plus
  • deebot_x5_pro
  • deebot_x5_pro_plus
  • deebot_x1_turbo
  • deebot_x1e_omni
  • deebot_x1s_pro_plus
  • deebot_t10
  • deebot_t10_plus_firmware
  • deebot_x1_pro_omni
  • deebot_x1s_pro_firmware
  • deebot_x2_pro_firmware
  • deebot_x1_firmware
  • deebot_x2_omni_firmware
  • mate_x
  • deebot_x1_turbo_firmware
  • mate_x_firmware
  • deebot_x2s_firmware
  • deebot_x1_plus_firmware
CWE
CWE-295

Improper Certificate Validation