Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2025-30199 ECOVACS vacuum robot base stations do not validate firmware updates, so malicious over-the-air updates can be sent to base station via insecure conne… Deebot X1s Pro Firmware 1.11.0 / 2.4.45+ Fix from $1,9502025-09-05 MEDIUM 6.3 CVE-2025-30198 ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic WPA2-PSK, which can be easily derived. Deebot X1s Pro Firmware 1.11.0 / 2.4.45+ Fix from $1,6002025-09-05 MEDIUM 6.3 CVE-2025-30200 ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic AES encryption key, which can be easily derive… Deebot X1s Pro Firmware 1.11.0 / 2.4.45+ Fix from $1,6002025-09-05 HIGH 7.5 CVE-2024-52331 ECOVACS robot lawnmowers and vacuums use a deterministic symmetric key to decrypt firmware updates. An attacker can create and encrypt malicious firm… Deebot 900 Firmware No fix yet Fix from $1,9502025-01-23 HIGH 7.4 CVE-2024-52329 ECOVACS HOME mobile app plugins for specific robots do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS tra… Home 3.0.0+ Fix from $1,9502025-01-23 HIGH 7.4 CVE-2024-52330 ECOVACS lawnmowers and vacuums do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic, possibly modify… Deebot X2 Omni Firmware 1.17.0 / 1.38.0+ Fix from $1,9502025-01-23 MEDIUM 6.5 CVE-2024-52327 The cloud service used by ECOVACS robot lawnmowers and vacuums allows authenticated attackers to bypass the PIN entry required to access the live vid… Home 3.0.2+ Fix from $1,6002025-01-23 MEDIUM 6.3 CVE-2024-12078 ECOVACS robot lawn mowers and vacuums use a shared, static secret key to encrypt BLE GATT messages. An unauthenticated attacker within BLE range can … Deebot N10 Firmware No fix yet Fix from $1,6002025-01-23 HIGH 7.6 CVE-2024-11147 ECOVACS robot lawnmowers and vacuums use a deterministic root password generated based on model and serial number. An attacker with shell access can … Deebot 900 Firmware No fix yet Fix from $1,9502025-01-23 CRITICAL 9.6 CVE-2024-52325 ECOVACS robot lawnmowers and vacuums are vulnerable to command injection via SetNetPin() over an unauthenticated BLE connection. Goat G1 2000 Firmware 1.2.120 / 1.36.187+ Fix from $2,3002025-01-23