Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.2
CVE-2025-30199
ECOVACS vacuum robot base stations do not validate firmware updates, so malicious over-the-air updates can be sent to base station via insecure conne…
Deebot X1s Pro Firmware
1.11.0 / 2.4.45+
MEDIUM 6.3
CVE-2025-30198
ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic WPA2-PSK, which can be easily derived.
Deebot X1s Pro Firmware
1.11.0 / 2.4.45+
MEDIUM 6.3
CVE-2025-30200
ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic AES encryption key, which can be easily derive…
Deebot X1s Pro Firmware
1.11.0 / 2.4.45+
HIGH 7.5
CVE-2024-52331
ECOVACS robot lawnmowers and vacuums use a deterministic symmetric key to decrypt firmware updates. An attacker can create and encrypt malicious firm…
Deebot 900 Firmware
No fix yet
HIGH 7.4
CVE-2024-52329
ECOVACS HOME mobile app plugins for specific robots do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS tra…
Home
3.0.0+
HIGH 7.4
CVE-2024-52330
ECOVACS lawnmowers and vacuums do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic, possibly modify…
Deebot X2 Omni Firmware
1.17.0 / 1.38.0+
MEDIUM 6.5
CVE-2024-52327
The cloud service used by ECOVACS robot lawnmowers and vacuums allows authenticated attackers to bypass the PIN entry required to access the live vid…
Home
3.0.2+
MEDIUM 6.3
CVE-2024-12078
ECOVACS robot lawn mowers and vacuums use a shared, static secret key to encrypt BLE GATT messages. An unauthenticated attacker within BLE range can …
Deebot N10 Firmware
No fix yet
HIGH 7.6
CVE-2024-11147
ECOVACS robot lawnmowers and vacuums use a deterministic root password generated based on model and serial number. An attacker with shell access can …
Deebot 900 Firmware
No fix yet
CRITICAL 9.6
CVE-2024-52325
ECOVACS robot lawnmowers and vacuums are vulnerable to command injection via SetNetPin() over an unauthenticated BLE connection.
Goat G1 2000 Firmware
1.2.120 / 1.36.187+