ECOVACS HOME mobile app plugins for specific robots do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic and obtain authentication tokens.
The ECOVACS HOME mobile application does not perform proper TLS certificate validation (CWE-295) during communication with robots. An unauthenticated attacker positioned on the network path (man-in-the-middle attack) can intercept encrypted TLS traffic or modify it. As a result, the attacker gains access to authentication tokens transmitted between the application and the device.
An attacker can read or modify TLS communication and intercept authentication tokens, which in practice means the ability to take control of the robot and access associated cloud services — potentially also within internal systems.
Apply patches available from the manufacturer according to the references: https://www.ecovacs.com/global/userhelp/dsa20241217001. Until the update is applied, it is recommended to avoid using the application on untrusted Wi-Fi networks.
ECOVACS HOME mobile application plugins supporting specific robot models — specific versions indicated in the manufacturer's references (DSA20241217001).
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XEcovacs Home
APPEcovacs< 3.0.0
Related vulnerabilities
The cloud service used by ECOVACS robot lawnmowers and vacuums allows authenticated attackers to bypass the PI...
Nieprawidłowa walidacja certyfikatów TLS w urządzeniach ECOVACS
ECOVACS vacuum robot base stations do not validate firmware updates, so malicious over-the-air updates can be ...
ECOVACS robot lawnmowers and vacuums use a deterministic symmetric key to decrypt firmware updates. An attacke...
ECOVACS robot lawnmowers and vacuums use a deterministic root password generated based on model and serial num...