Vulnerabilities (CVE)

Filtered by vendor Ecovacs Subscribe
Filtered by product Deebot X2 Combo
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-52330 1 Ecovacs 40 Deebot T10, Deebot T10 Firmware, Deebot T10 Omni and 37 more 2025-09-23 N/A 7.4 HIGH
ECOVACS lawnmowers and vacuums do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic, possibly modifying firmware updates.
CVE-2024-52325 1 Ecovacs 24 Deebot T30 Omni, Deebot T30 Omni Firmware, Deebot T30s and 21 more 2025-09-23 N/A 9.6 CRITICAL
ECOVACS robot lawnmowers and vacuums are vulnerable to command injection via SetNetPin() over an unauthenticated BLE connection.