CVE-2024-52325

ECOVACS robot lawnmowers and vacuums are vulnerable to command injection via SetNetPin() over an unauthenticated BLE connection.
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.6 CRITICAL
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
cisa-cgCNA
9.6 CRITICAL
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 83%
VendorProductVersion
ecovacsgoat_g1-2000_firmware
𝑥
< 1.36.187
ecovacsgoat_g1_firmware
𝑥
< 1.36.187
ecovacsgoat_g1-800_firmware
𝑥
< 1.36.187
ecovacsgx-600_firmware
𝑥
< 1.2.120
ecovacsdeebot_x2_omni_firmware
𝑥
< 1.76.6
ecovacsdeebot_x2_combo_firmware
𝑥
< 1.81.10
ecovacsdeebot_x2s_firmware
𝑥
< 1.49.0
ecovacsdeebot_x5_pro_firmware
𝑥
< 1.70.0
ecovacsdeebot_x5_pro_plus_firmware
𝑥
< 1.38.0
ecovacsdeebot_x5_pro_ultra_firmware
𝑥
< 1.17.0
ecovacsdeebot_t30_omni_firmware
𝑥
< 1.93.0
ecovacsdeebot_t30s_firmware
𝑥
< 1.95.0
𝑥
= Vulnerable software versions