CVE-2025-30199
05.09.2025, 18:15
ECOVACS vacuum robot base stations do not validate firmware updates, so malicious over-the-air updates can be sent to base station via insecure connection between robot and base station.Enginsight
Vendor | Product | Version |
---|---|---|
ecovacs | deebot_x1s_pro_firmware | 𝑥 < 2.5.38 |
ecovacs | deebot_x1_pro_omni_firmware | 𝑥 < 2.5.38 |
ecovacs | deebot_x1_omni_firmware | 𝑥 < 2.4.45 |
ecovacs | deebot_x1s_pro_firmware | 𝑥 < 2.4.45 |
ecovacs | deebot_x1_turbo_firmware | 𝑥 < 2.5.38 |
ecovacs | deebot_x1s_pro_firmware | 𝑥 < 2.4.45 |
ecovacs | deebot_t10_firmware | 𝑥 < 1.11.0 |
ecovacs | deebot_t10_omni_firmware | 𝑥 < 1.11.0 |
ecovacs | deebot_t10_plus_firmware | 𝑥 < 1.11.0 |
ecovacs | deebot_t10_turbo_firmware | 𝑥 < 1.11.0 |
ecovacs | deebot_t20_omni_firmware | 𝑥 < 1.25.0 |
ecovacs | deebot_t20_pro_plus_firmware | 𝑥 < 1.25.0 |
ecovacs | deebot_t20_pro_firmware | 𝑥 < 1.25.0 |
ecovacs | deebot_t30_omni_firmware | 𝑥 < 1.100.0 |
ecovacs | deebot_t30s_firmware | 𝑥 < 1.100.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration