PT-2025-2926 · Ecovacs · Ecovacs

Published

2025-01-23

·

Updated

2025-01-23

·

CVE-2024-52328

CVSS v3.1

2.3

Low

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions ECOVACS robot lawnmowers and vacuums (affected versions not specified)
Description The issue concerns the insecure storage of audio files used to indicate when the camera is on in ECOVACS robots. An attacker with access to the /data filesystem can delete or modify these warning files, potentially leaving users unaware that the camera is active.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Permission

Weakness Enumeration

Related Identifiers

CVE-2024-52328

Affected Products

Ecovacs