ECOVACS lawnmowers and vacuums do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic, possibly modifying firmware updates.
References
Link | Resource |
---|---|
https://dontvacuum.me/talks/37c3-2023/37c3-vacuuming-and-mowing.pdf | Exploit Third Party Advisory |
https://dontvacuum.me/talks/HITCON2024/HITCON-CMT-2024_Ecovacs.pdf | Exploit Third Party Advisory |
https://www.ecovacs.com/global/userhelp/dsa20241217001 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
AND |
|
Configuration 10 (hide)
AND |
|
Configuration 11 (hide)
AND |
|
Configuration 12 (hide)
AND |
|
Configuration 13 (hide)
AND |
|
Configuration 14 (hide)
AND |
|
Configuration 15 (hide)
AND |
|
Configuration 16 (hide)
AND |
|
Configuration 17 (hide)
AND |
|
Configuration 18 (hide)
AND |
|
Configuration 19 (hide)
AND |
|
Configuration 20 (hide)
AND |
|
History
23 Sep 2025, 17:48
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:ecovacs:deebot_x1e_omni_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x5_pro_ultra:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x1_omni:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_t10_turbo:-:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x1s_pro_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x5_pro_ultra_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x2s_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x1_turbo_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x1s_pro_plus_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x2s:-:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x1_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_t10_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x2_omni_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_t10_omni:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x5_pro_plus:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x2_omni:-:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x5_pro_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_t10_omni_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x2_combo:-:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:mate_x_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x1_pro_omni_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x1_pro_omni:-:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x2_combo_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:mate_x:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x5_pro:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x1e_omni:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x1_plus:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x1_turbo:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x1:-:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_t10_turbo_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x2_pro_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x5_pro_plus_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_t10_plus_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x1_plus_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_t10_plus:-:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x1_omni_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_t10:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x2_pro:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x1s_pro:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x1s_pro_plus:-:*:*:*:*:*:*:* |
|
Summary |
|
|
First Time |
Ecovacs mate X Firmware
Ecovacs deebot X1s Pro Plus Firmware Ecovacs deebot X1 Pro Omni Ecovacs deebot X5 Pro Ultra Firmware Ecovacs deebot X1 Omni Ecovacs deebot X5 Pro Ecovacs Ecovacs deebot X2 Combo Ecovacs deebot X1 Ecovacs deebot X2 Combo Firmware Ecovacs deebot X5 Pro Firmware Ecovacs deebot X2s Firmware Ecovacs deebot T10 Turbo Firmware Ecovacs mate X Ecovacs deebot X1 Firmware Ecovacs deebot T10 Ecovacs deebot X5 Pro Ultra Ecovacs deebot T10 Plus Firmware Ecovacs deebot X2 Omni Firmware Ecovacs deebot X1 Pro Omni Firmware Ecovacs deebot X5 Pro Plus Firmware Ecovacs deebot X1 Plus Ecovacs deebot X1 Turbo Ecovacs deebot X1e Omni Firmware Ecovacs deebot T10 Turbo Ecovacs deebot X1s Pro Firmware Ecovacs deebot X2 Pro Ecovacs deebot X5 Pro Plus Ecovacs deebot X2 Pro Firmware Ecovacs deebot T10 Omni Firmware Ecovacs deebot X1s Pro Plus Ecovacs deebot T10 Firmware Ecovacs deebot X2s Ecovacs deebot T10 Plus Ecovacs deebot X2 Omni Ecovacs deebot X1 Omni Firmware Ecovacs deebot X1e Omni Ecovacs deebot X1 Plus Firmware Ecovacs deebot X1 Turbo Firmware Ecovacs deebot X1s Pro Ecovacs deebot T10 Omni |
|
References | () https://dontvacuum.me/talks/37c3-2023/37c3-vacuuming-and-mowing.pdf - Exploit, Third Party Advisory | |
References | () https://dontvacuum.me/talks/HITCON2024/HITCON-CMT-2024_Ecovacs.pdf - Exploit, Third Party Advisory | |
References | () https://www.ecovacs.com/global/userhelp/dsa20241217001 - Vendor Advisory |
23 Jan 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-01-23 17:15
Updated : 2025-09-23 17:48
NVD link : CVE-2024-52330
Mitre link : CVE-2024-52330
CVE.ORG link : CVE-2024-52330
JSON object : View
Products Affected
ecovacs
- deebot_x5_pro_firmware
- deebot_t10_plus
- deebot_x1e_omni_firmware
- deebot_x2_pro
- deebot_x1_omni
- deebot_x1s_pro
- deebot_x1_pro_omni_firmware
- deebot_x2_combo
- deebot_x5_pro_ultra_firmware
- deebot_x1_omni_firmware
- deebot_x1
- deebot_x2s
- deebot_x1s_pro_plus_firmware
- deebot_x5_pro_plus_firmware
- deebot_t10_firmware
- deebot_t10_omni_firmware
- deebot_t10_turbo
- deebot_t10_omni
- deebot_x5_pro_ultra
- deebot_t10_turbo_firmware
- deebot_x2_combo_firmware
- deebot_x2_omni
- deebot_x1_plus
- deebot_x5_pro
- deebot_x5_pro_plus
- deebot_x1_turbo
- deebot_x1e_omni
- deebot_x1s_pro_plus
- deebot_t10
- deebot_t10_plus_firmware
- deebot_x1_pro_omni
- deebot_x1s_pro_firmware
- deebot_x2_pro_firmware
- deebot_x1_firmware
- deebot_x2_omni_firmware
- mate_x
- deebot_x1_turbo_firmware
- mate_x_firmware
- deebot_x2s_firmware
- deebot_x1_plus_firmware
CWE
CWE-295
Improper Certificate Validation