ECOVACS lawnmowers and vacuums do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic, possibly modifying firmware updates.
Metrics
Affected Vendors & Products
References
History
Tue, 23 Sep 2025 18:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Ecovacs
Ecovacs deebot T10 Ecovacs deebot T10 Firmware Ecovacs deebot T10 Omni Ecovacs deebot T10 Omni Firmware Ecovacs deebot T10 Plus Ecovacs deebot T10 Plus Firmware Ecovacs deebot T10 Turbo Ecovacs deebot T10 Turbo Firmware Ecovacs deebot X1 Ecovacs deebot X1 Firmware Ecovacs deebot X1 Omni Ecovacs deebot X1 Omni Firmware Ecovacs deebot X1 Plus Ecovacs deebot X1 Plus Firmware Ecovacs deebot X1 Pro Omni Ecovacs deebot X1 Pro Omni Firmware Ecovacs deebot X1 Turbo Ecovacs deebot X1 Turbo Firmware Ecovacs deebot X1e Omni Ecovacs deebot X1e Omni Firmware Ecovacs deebot X1s Pro Ecovacs deebot X1s Pro Firmware Ecovacs deebot X1s Pro Plus Ecovacs deebot X1s Pro Plus Firmware Ecovacs deebot X2 Combo Ecovacs deebot X2 Combo Firmware Ecovacs deebot X2 Omni Ecovacs deebot X2 Omni Firmware Ecovacs deebot X2 Pro Ecovacs deebot X2 Pro Firmware Ecovacs deebot X2s Ecovacs deebot X2s Firmware Ecovacs deebot X5 Pro Ecovacs deebot X5 Pro Firmware Ecovacs deebot X5 Pro Plus Ecovacs deebot X5 Pro Plus Firmware Ecovacs deebot X5 Pro Ultra Ecovacs deebot X5 Pro Ultra Firmware Ecovacs mate X Ecovacs mate X Firmware |
|
CPEs | cpe:2.3:h:ecovacs:deebot_t10:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_t10_omni:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_t10_plus:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_t10_turbo:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x1:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x1_omni:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x1_plus:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x1_pro_omni:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x1_turbo:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x1e_omni:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x1s_pro:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x1s_pro_plus:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x2_combo:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x2_omni:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x2_pro:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x2s:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x5_pro:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x5_pro_plus:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x5_pro_ultra:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:mate_x:-:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_t10_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_t10_omni_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_t10_plus_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_t10_turbo_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x1_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x1_omni_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x1_plus_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x1_pro_omni_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x1_turbo_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x1e_omni_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x1s_pro_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x1s_pro_plus_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x2_combo_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x2_omni_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x2_pro_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x2s_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x5_pro_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x5_pro_plus_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x5_pro_ultra_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:mate_x_firmware:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Ecovacs
Ecovacs deebot T10 Ecovacs deebot T10 Firmware Ecovacs deebot T10 Omni Ecovacs deebot T10 Omni Firmware Ecovacs deebot T10 Plus Ecovacs deebot T10 Plus Firmware Ecovacs deebot T10 Turbo Ecovacs deebot T10 Turbo Firmware Ecovacs deebot X1 Ecovacs deebot X1 Firmware Ecovacs deebot X1 Omni Ecovacs deebot X1 Omni Firmware Ecovacs deebot X1 Plus Ecovacs deebot X1 Plus Firmware Ecovacs deebot X1 Pro Omni Ecovacs deebot X1 Pro Omni Firmware Ecovacs deebot X1 Turbo Ecovacs deebot X1 Turbo Firmware Ecovacs deebot X1e Omni Ecovacs deebot X1e Omni Firmware Ecovacs deebot X1s Pro Ecovacs deebot X1s Pro Firmware Ecovacs deebot X1s Pro Plus Ecovacs deebot X1s Pro Plus Firmware Ecovacs deebot X2 Combo Ecovacs deebot X2 Combo Firmware Ecovacs deebot X2 Omni Ecovacs deebot X2 Omni Firmware Ecovacs deebot X2 Pro Ecovacs deebot X2 Pro Firmware Ecovacs deebot X2s Ecovacs deebot X2s Firmware Ecovacs deebot X5 Pro Ecovacs deebot X5 Pro Firmware Ecovacs deebot X5 Pro Plus Ecovacs deebot X5 Pro Plus Firmware Ecovacs deebot X5 Pro Ultra Ecovacs deebot X5 Pro Ultra Firmware Ecovacs mate X Ecovacs mate X Firmware |
Wed, 12 Feb 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 23 Jan 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | ECOVACS lawnmowers and vacuums do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic, possibly modifying firmware updates. | |
Title | ECOVACS lawnmowers and vacuums do not properly validate TLS certificates | |
Weaknesses | CWE-295 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: cisa-cg
Published: 2025-01-23T16:36:50.128Z
Updated: 2025-02-12T20:41:28.969Z
Reserved: 2024-11-08T01:06:02.405Z
Link: CVE-2024-52330

Updated: 2025-02-12T20:35:32.396Z

Status : Analyzed
Published: 2025-01-23T17:15:14.427
Modified: 2025-09-23T17:48:33.127
Link: CVE-2024-52330

No data.