PT-2025-2929 · Ecovacs · Ecovacs

Braelynn Luedtke

+1

·

Published

2025-01-23

·

Updated

2025-10-02

·

CVE-2024-52331

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ECOVACS robot lawnmowers and vacuums (affected versions not specified)
Description The issue concerns the use of a deterministic symmetric key for decrypting firmware updates in ECOVACS robots. This allows an attacker to create and encrypt malicious firmware, which can then be successfully decrypted and installed by the robot.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use of a Broken Cryptographic Algorithm

Weakness Enumeration

Related Identifiers

CVE-2024-52331

Affected Products

Ecovacs