CVE-2024-52331
23.01.2025, 17:15
ECOVACS robot lawnmowers and vacuums use a deterministic symmetric key to decrypt firmware updates. An attacker can create and encrypt malicious firmware that will be successfully decrypted and installed by the robot.Enginsight
| Vendor | Product | Version |
|---|---|---|
| ecovacs | deebot_900_firmware | - |
| ecovacs | deebot_n8_firmware | - |
| ecovacs | deebot_t8_firmware | - |
| ecovacs | deebot_n9_firmware | - |
| ecovacs | deebot_t9_firmware | - |
| ecovacs | deebot_n10_firmware | - |
| ecovacs | deebot_t10_firmware | - |
| ecovacs | deebot_x1_firmware | - |
| ecovacs | deebot_t20_firmware | - |
| ecovacs | deebot_x2_firmware | - |
| ecovacs | goat_g1_firmware | - |
| ecovacs | airbot_z1_firmware | - |
| ecovacs | airbot_ava_firmware | - |
| ecovacs | airbot_andy_firmware | - |
𝑥
= Vulnerable software versions
Common Weakness Enumeration