ECOVACS robot lawnmowers and vacuums are vulnerable to command injection via SetNetPin() over an unauthenticated BLE connection.
Metrics
Affected Vendors & Products
References
History
Tue, 23 Sep 2025 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Ecovacs
Ecovacs deebot T30 Omni Ecovacs deebot T30 Omni Firmware Ecovacs deebot T30s Ecovacs deebot T30s Firmware Ecovacs deebot X2 Combo Ecovacs deebot X2 Combo Firmware Ecovacs deebot X2 Omni Ecovacs deebot X2 Omni Firmware Ecovacs deebot X2s Ecovacs deebot X2s Firmware Ecovacs deebot X5 Pro Ecovacs deebot X5 Pro Firmware Ecovacs deebot X5 Pro Plus Ecovacs deebot X5 Pro Plus Firmware Ecovacs deebot X5 Pro Ultra Ecovacs deebot X5 Pro Ultra Firmware Ecovacs goat G1 Ecovacs goat G1-2000 Ecovacs goat G1-2000 Firmware Ecovacs goat G1-800 Ecovacs goat G1-800 Firmware Ecovacs goat G1 Firmware Ecovacs gx-600 Ecovacs gx-600 Firmware |
|
CPEs | cpe:2.3:h:ecovacs:deebot_t30_omni:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_t30s:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x2_combo:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x2_omni:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x2s:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x5_pro:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x5_pro_plus:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:deebot_x5_pro_ultra:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:goat_g1-2000:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:goat_g1-800:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:goat_g1:-:*:*:*:*:*:*:* cpe:2.3:h:ecovacs:gx-600:-:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_t30_omni_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_t30s_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x2_combo_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x2_omni_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x2s_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x5_pro_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x5_pro_plus_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:deebot_x5_pro_ultra_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:goat_g1-2000_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:goat_g1-800_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:goat_g1_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:ecovacs:gx-600_firmware:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Ecovacs
Ecovacs deebot T30 Omni Ecovacs deebot T30 Omni Firmware Ecovacs deebot T30s Ecovacs deebot T30s Firmware Ecovacs deebot X2 Combo Ecovacs deebot X2 Combo Firmware Ecovacs deebot X2 Omni Ecovacs deebot X2 Omni Firmware Ecovacs deebot X2s Ecovacs deebot X2s Firmware Ecovacs deebot X5 Pro Ecovacs deebot X5 Pro Firmware Ecovacs deebot X5 Pro Plus Ecovacs deebot X5 Pro Plus Firmware Ecovacs deebot X5 Pro Ultra Ecovacs deebot X5 Pro Ultra Firmware Ecovacs goat G1 Ecovacs goat G1-2000 Ecovacs goat G1-2000 Firmware Ecovacs goat G1-800 Ecovacs goat G1-800 Firmware Ecovacs goat G1 Firmware Ecovacs gx-600 Ecovacs gx-600 Firmware |
Wed, 12 Feb 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 23 Jan 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | ECOVACS robot lawnmowers and vacuums are vulnerable to command injection via SetNetPin() over an unauthenticated BLE connection. | |
Title | ECOVACS robot lawnmowers and vacuums command injection | |
Weaknesses | CWE-77 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: cisa-cg
Published:
Updated: 2025-02-12T20:41:26.651Z
Reserved: 2024-11-08T01:06:02.404Z
Link: CVE-2024-52325

Updated: 2025-02-12T20:34:47.477Z

Status : Analyzed
Published: 2025-01-23T16:15:35.943
Modified: 2025-09-23T17:35:35.463
Link: CVE-2024-52325

No data.