PT-2025-22570 · Ecovacs · Ecovacs Home
Published
2025-05-23
·
Updated
2025-05-23
·
CVE-2025-2394
CVSS v4.0
4.7
Medium
| Vector | AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Ecovacs Home Android and iOS Mobile Applications versions up to 3.3.0
Description
The issue concerns the disclosure of sensitive data due to embedded access keys and secrets for Alibaba Object Storage Service (OSS) in the Ecovacs Home mobile applications.
Recommendations
For versions up to 3.3.0, consider removing or securely storing the embedded access keys and secrets for Alibaba Object Storage Service (OSS) to prevent sensitive data disclosure.
As a temporary workaround, restrict access to the Alibaba Object Storage Service (OSS) until a secure update is available.
Fix
Insufficiently Protected Credentials
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ecovacs Home