ECOVACS lawnmowers and vacuums do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic, possibly modifying firmware updates.
The vulnerability stems from improper implementation of TLS certificate validation (CWE-295 — Improper Certificate Validation). An attacker positioned in the network communication path of the device (man-in-the-middle attack) can impersonate manufacturer servers by presenting a fraudulent TLS certificate that will not be rejected by the device. As a result, the attacker can read or modify transmitted data, including potentially substituting firmware update packages.
An attacker can intercept or modify TLS traffic of the device, and in the most dangerous scenario deliver manipulated firmware, taking control of the device or systems it interacts with.
Apply patches available from the manufacturer according to references — ECOVACS security advisory: https://www.ecovacs.com/global/userhelp/dsa20241217001. Until the update is installed, restrict device access to unknown/public networks and implement network segmentation.
Ecovacs Deebot X2 Omni (Firmware), Ecovacs Deebot X2 Combo (Firmware), Ecovacs Deebot X2S (Firmware) — specific versions indicated in manufacturer references (DSA20241217001)
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XEcovacs Deebot T10
HWEcovacsall versionsEcovacs Deebot T10 Firmware
OSEcovacs< 1.7.5Ecovacs Deebot T10 Omni
HWEcovacsall versionsEcovacs Deebot T10 Omni Firmware
OSEcovacs< 1.9.0Ecovacs Deebot T10 Plus
HWEcovacsall versionsEcovacs Deebot T10 Plus Firmware
OSEcovacs< 1.7.5Ecovacs Deebot T10 Turbo
HWEcovacsall versionsEcovacs Deebot T10 Turbo Firmware
OSEcovacs< 1.10.0Ecovacs Deebot X1
HWEcovacsall versionsEcovacs Deebot X1e Omni
HWEcovacsall versionsEcovacs Deebot X1e Omni Firmware
OSEcovacs< 2.4.42Ecovacs Deebot X1 Firmware
OSEcovacs< 1.7.3Ecovacs Deebot X1 Omni
HWEcovacsall versionsEcovacs Deebot X1 Omni Firmware
OSEcovacs< 2.4.41Ecovacs Deebot X1 Plus
HWEcovacsall versionsEcovacs Deebot X1 Plus Firmware
OSEcovacs< 1.7.3Ecovacs Deebot X1 Pro Omni
HWEcovacsall versionsEcovacs Deebot X1 Pro Omni Firmware
OSEcovacs< 2.4.41Ecovacs Deebot X1s Pro
HWEcovacsall versionsEcovacs Deebot X1s Pro Firmware
OSEcovacs< 2.5.31Ecovacs Deebot X1s Pro Plus
HWEcovacsall versionsEcovacs Deebot X1s Pro Plus Firmware
OSEcovacs< 1.23.0Ecovacs Deebot X1 Turbo
HWEcovacsall versionsEcovacs Deebot X1 Turbo Firmware
OSEcovacs< 2.4.41Ecovacs Deebot X2 Combo
HWEcovacsall versionsEcovacs Deebot X2 Combo Firmware
OSEcovacs< 1.81.10Ecovacs Deebot X2 Omni
HWEcovacsall versionsEcovacs Deebot X2 Omni Firmware
OSEcovacs< 1.76.6Ecovacs Deebot X2 Pro
HWEcovacsall versionsEcovacs Deebot X2 Pro Firmware
OSEcovacs< 1.76.6
Related vulnerabilities
ECOVACS vacuum robot base stations do not validate firmware updates, so malicious over-the-air updates can be ...
ECOVACS robot lawnmowers and vacuums use a deterministic root password generated based on model and serial num...
ECOVACS robot lawnmowers and vacuums use a deterministic symmetric key to decrypt firmware updates. An attacke...
ECOVACS robot lawn mowers and vacuums use a shared, static secret key to encrypt BLE GATT messages. An unauthe...
ECOVACS robot lawnmowers store the anti-theft PIN in cleartext on the device filesystem. An attacker can steal...