ECOVACS robot lawn mowers and vacuums use a shared, static secret key to encrypt BLE GATT messages. An unauthenticated attacker within BLE range can control any robot using the same key.
Metrics
Affected Vendors & Products
References
History
Tue, 23 Sep 2025 18:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Ecovacs
Ecovacs airbot Andy Ecovacs airbot Andy Firmware Ecovacs airbot Ava Ecovacs airbot Ava Firmware Ecovacs airbot Z1 Ecovacs airbot Z1 Firmware Ecovacs deebot 900 Ecovacs deebot 900 Firmware Ecovacs deebot N10 Ecovacs deebot N10 Firmware Ecovacs deebot N8 Ecovacs deebot N8 Firmware Ecovacs deebot N9 Ecovacs deebot N9 Firmware Ecovacs deebot T10 Ecovacs deebot T10 Firmware Ecovacs deebot T20 Ecovacs deebot T20 Firmware Ecovacs deebot T8 Ecovacs deebot T8 Firmware Ecovacs deebot T9 Ecovacs deebot T9 Firmware Ecovacs deebot X1 Ecovacs deebot X1 Firmware Ecovacs deebot X2 Ecovacs deebot X2 Firmware Ecovacs goat G1 Ecovacs goat G1 Firmware |
|
CPEs | cpe:2.3:h:ecovacs:airbot_andy:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:airbot_ava:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:airbot_z1:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_900:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_n10:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_n8:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_n9:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_t10:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_t20:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_t8:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_t9:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x1:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x2:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:goat_g1:-:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:airbot_andy_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:airbot_ava_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:airbot_z1_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_900_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_n10_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_n8_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_n9_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_t10_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_t20_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_t8_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_t9_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x1_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x2_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:goat_g1_firmware:-:*:*:*:*:*:*:* |
|
Vendors & Products |
Ecovacs
Ecovacs airbot Andy Ecovacs airbot Andy Firmware Ecovacs airbot Ava Ecovacs airbot Ava Firmware Ecovacs airbot Z1 Ecovacs airbot Z1 Firmware Ecovacs deebot 900 Ecovacs deebot 900 Firmware Ecovacs deebot N10 Ecovacs deebot N10 Firmware Ecovacs deebot N8 Ecovacs deebot N8 Firmware Ecovacs deebot N9 Ecovacs deebot N9 Firmware Ecovacs deebot T10 Ecovacs deebot T10 Firmware Ecovacs deebot T20 Ecovacs deebot T20 Firmware Ecovacs deebot T8 Ecovacs deebot T8 Firmware Ecovacs deebot T9 Ecovacs deebot T9 Firmware Ecovacs deebot X1 Ecovacs deebot X1 Firmware Ecovacs deebot X2 Ecovacs deebot X2 Firmware Ecovacs goat G1 Ecovacs goat G1 Firmware |
Wed, 12 Feb 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 23 Jan 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | ECOVACS robot lawn mowers and vacuums use a shared, static secret key to encrypt BLE GATT messages. An unauthenticated attacker within BLE range can control any robot using the same key. | |
Title | ECOVACS lawnmowers and vacuums static BLE GATT encryption key | |
Weaknesses | CWE-321 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: cisa-cg
Published:
Updated: 2025-02-12T17:11:14.933Z
Reserved: 2024-12-02T23:55:12.974Z
Link: CVE-2024-12078

Updated: 2025-02-12T17:11:05.672Z

Status : Analyzed
Published: 2025-01-23T17:15:13.020
Modified: 2025-09-23T17:45:19.900
Link: CVE-2024-12078

No data.