CRITICAL🇵🇱 Wersja polska

CVE-2024-52329

CVSS 9.5v4.0pub. 2025-01-23upd. 2025-09-23

ECOVACS HOME mobile app plugins for specific robots do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic and obtain authentication tokens.

🤖 AI Analysis
How it works

The ECOVACS HOME mobile application does not perform proper TLS certificate validation (CWE-295) during communication with robots. An unauthenticated attacker positioned on the network path (man-in-the-middle attack) can intercept encrypted TLS traffic or modify it. As a result, the attacker gains access to authentication tokens transmitted between the application and the device.

Impact

An attacker can read or modify TLS communication and intercept authentication tokens, which in practice means the ability to take control of the robot and access associated cloud services — potentially also within internal systems.

Mitigation & patch

Apply patches available from the manufacturer according to the references: https://www.ecovacs.com/global/userhelp/dsa20241217001. Until the update is applied, it is recommended to avoid using the application on untrusted Wi-Fi networks.

Who is affected

ECOVACS HOME mobile application plugins supporting specific robot models — specific versions indicated in the manufacturer's references (DSA20241217001).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Ecovacs Home

    APP
    Ecovacs
    < 3.0.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2024-52327MEDIUM6.0same product

The cloud service used by ECOVACS robot lawnmowers and vacuums allows authenticated attackers to bypass the PI...

CVE-2024-52330CRITICAL9.5PL ✓same vendor

Nieprawidłowa walidacja certyfikatów TLS w urządzeniach ECOVACS

CVE-2025-30199HIGH7.5same vendor

ECOVACS vacuum robot base stations do not validate firmware updates, so malicious over-the-air updates can be ...

CVE-2024-52331HIGH7.7same vendor

ECOVACS robot lawnmowers and vacuums use a deterministic symmetric key to decrypt firmware updates. An attacke...

CVE-2024-11147HIGH7.0same vendor

ECOVACS robot lawnmowers and vacuums use a deterministic root password generated based on model and serial num...