ECOVACS vacuum robot base stations do not validate firmware updates, so malicious over-the-air updates can be sent to base station via insecure connection between robot and base station.
History

Tue, 23 Sep 2025 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Ecovacs
Ecovacs deebot T10
Ecovacs deebot T10 Firmware
Ecovacs deebot T10 Omni
Ecovacs deebot T10 Omni Firmware
Ecovacs deebot T10 Plus
Ecovacs deebot T10 Plus Firmware
Ecovacs deebot T10 Turbo
Ecovacs deebot T10 Turbo Firmware
Ecovacs deebot T20 Omni
Ecovacs deebot T20 Omni Firmware
Ecovacs deebot T20 Pro
Ecovacs deebot T20 Pro Firmware
Ecovacs deebot T20 Pro Plus
Ecovacs deebot T20 Pro Plus Firmware
Ecovacs deebot T30 Omni
Ecovacs deebot T30 Omni Firmware
Ecovacs deebot T30s
Ecovacs deebot T30s Firmware
Ecovacs deebot X1 Omni
Ecovacs deebot X1 Omni Firmware
Ecovacs deebot X1 Pro Omni
Ecovacs deebot X1 Pro Omni Firmware
Ecovacs deebot X1 Turbo
Ecovacs deebot X1 Turbo Firmware
Ecovacs deebot X1s Pro
Ecovacs deebot X1s Pro Firmware
CPEs cpe:2.3:h:ecovacs:deebot_t10:-:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_t10_omni:-:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_t10_plus:-:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_t10_turbo:-:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_t20_omni:-:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_t20_pro:-:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_t20_pro_plus:-:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_t30_omni:-:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_t30s:-:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x1_omni:-:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x1_pro_omni:-:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x1_turbo:-:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x1s_pro:-:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_t10_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_t10_omni_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_t10_plus_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_t10_turbo_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_t20_omni_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_t20_pro_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_t20_pro_plus_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_t30_omni_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_t30s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_x1_omni_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_x1_pro_omni_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_x1_turbo_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_x1s_pro_firmware:*:*:*:*:*:*:*:*
Vendors & Products Ecovacs
Ecovacs deebot T10
Ecovacs deebot T10 Firmware
Ecovacs deebot T10 Omni
Ecovacs deebot T10 Omni Firmware
Ecovacs deebot T10 Plus
Ecovacs deebot T10 Plus Firmware
Ecovacs deebot T10 Turbo
Ecovacs deebot T10 Turbo Firmware
Ecovacs deebot T20 Omni
Ecovacs deebot T20 Omni Firmware
Ecovacs deebot T20 Pro
Ecovacs deebot T20 Pro Firmware
Ecovacs deebot T20 Pro Plus
Ecovacs deebot T20 Pro Plus Firmware
Ecovacs deebot T30 Omni
Ecovacs deebot T30 Omni Firmware
Ecovacs deebot T30s
Ecovacs deebot T30s Firmware
Ecovacs deebot X1 Omni
Ecovacs deebot X1 Omni Firmware
Ecovacs deebot X1 Pro Omni
Ecovacs deebot X1 Pro Omni Firmware
Ecovacs deebot X1 Turbo
Ecovacs deebot X1 Turbo Firmware
Ecovacs deebot X1s Pro
Ecovacs deebot X1s Pro Firmware

Mon, 08 Sep 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 05 Sep 2025 18:00:00 +0000

Type Values Removed Values Added
Description ECOVACS vacuum robot base stations do not validate firmware updates, so malicious over-the-air updates can be sent to base station via insecure connection between robot and base station.
Title ECOVACS Vacuum and Base Station accept unsigned firmware
Weaknesses CWE-494
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published: 2025-09-05T17:45:07.227Z

Updated: 2025-09-08T18:21:06.626Z

Reserved: 2025-03-18T15:53:08.738Z

Link: CVE-2025-30199

cve-icon Vulnrichment

Updated: 2025-09-08T18:20:56.020Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-05T18:15:39.553

Modified: 2025-09-23T17:11:48.730

Link: CVE-2025-30199

cve-icon Redhat

No data.