ECOVACS robot lawnmowers and vacuums are vulnerable to command injection via SetNetPin() over an unauthenticated BLE connection.
History

Tue, 23 Sep 2025 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Ecovacs
Ecovacs deebot T30 Omni
Ecovacs deebot T30 Omni Firmware
Ecovacs deebot T30s
Ecovacs deebot T30s Firmware
Ecovacs deebot X2 Combo
Ecovacs deebot X2 Combo Firmware
Ecovacs deebot X2 Omni
Ecovacs deebot X2 Omni Firmware
Ecovacs deebot X2s
Ecovacs deebot X2s Firmware
Ecovacs deebot X5 Pro
Ecovacs deebot X5 Pro Firmware
Ecovacs deebot X5 Pro Plus
Ecovacs deebot X5 Pro Plus Firmware
Ecovacs deebot X5 Pro Ultra
Ecovacs deebot X5 Pro Ultra Firmware
Ecovacs goat G1
Ecovacs goat G1-2000
Ecovacs goat G1-2000 Firmware
Ecovacs goat G1-800
Ecovacs goat G1-800 Firmware
Ecovacs goat G1 Firmware
Ecovacs gx-600
Ecovacs gx-600 Firmware
CPEs cpe:2.3:h:ecovacs:deebot_t30_omni:-:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_t30s:-:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x2_combo:-:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x2_omni:-:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x2s:-:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x5_pro:-:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x5_pro_plus:-:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:deebot_x5_pro_ultra:-:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:goat_g1-2000:-:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:goat_g1-800:-:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:goat_g1:-:*:*:*:*:*:*:*
cpe:2.3:h:ecovacs:gx-600:-:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_t30_omni_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_t30s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_x2_combo_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_x2_omni_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_x2s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_x5_pro_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_x5_pro_plus_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:deebot_x5_pro_ultra_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:goat_g1-2000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:goat_g1-800_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:goat_g1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ecovacs:gx-600_firmware:*:*:*:*:*:*:*:*
Vendors & Products Ecovacs
Ecovacs deebot T30 Omni
Ecovacs deebot T30 Omni Firmware
Ecovacs deebot T30s
Ecovacs deebot T30s Firmware
Ecovacs deebot X2 Combo
Ecovacs deebot X2 Combo Firmware
Ecovacs deebot X2 Omni
Ecovacs deebot X2 Omni Firmware
Ecovacs deebot X2s
Ecovacs deebot X2s Firmware
Ecovacs deebot X5 Pro
Ecovacs deebot X5 Pro Firmware
Ecovacs deebot X5 Pro Plus
Ecovacs deebot X5 Pro Plus Firmware
Ecovacs deebot X5 Pro Ultra
Ecovacs deebot X5 Pro Ultra Firmware
Ecovacs goat G1
Ecovacs goat G1-2000
Ecovacs goat G1-2000 Firmware
Ecovacs goat G1-800
Ecovacs goat G1-800 Firmware
Ecovacs goat G1 Firmware
Ecovacs gx-600
Ecovacs gx-600 Firmware

Wed, 12 Feb 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jan 2025 16:15:00 +0000

Type Values Removed Values Added
Description ECOVACS robot lawnmowers and vacuums are vulnerable to command injection via SetNetPin() over an unauthenticated BLE connection.
Title ECOVACS robot lawnmowers and vacuums command injection
Weaknesses CWE-77
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 5.8, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2025-02-12T20:41:26.651Z

Reserved: 2024-11-08T01:06:02.404Z

Link: CVE-2024-52325

cve-icon Vulnrichment

Updated: 2025-02-12T20:34:47.477Z

cve-icon NVD

Status : Analyzed

Published: 2025-01-23T16:15:35.943

Modified: 2025-09-23T17:35:35.463

Link: CVE-2024-52325

cve-icon Redhat

No data.