CRITICAL🇵🇱 Wersja polska

CVE-2024-52330

CVSS 9.5v4.0pub. 2025-01-23upd. 2025-09-23

ECOVACS lawnmowers and vacuums do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic, possibly modifying firmware updates.

🤖 AI Analysis
How it works

The vulnerability stems from improper implementation of TLS certificate validation (CWE-295 — Improper Certificate Validation). An attacker positioned in the network communication path of the device (man-in-the-middle attack) can impersonate manufacturer servers by presenting a fraudulent TLS certificate that will not be rejected by the device. As a result, the attacker can read or modify transmitted data, including potentially substituting firmware update packages.

Impact

An attacker can intercept or modify TLS traffic of the device, and in the most dangerous scenario deliver manipulated firmware, taking control of the device or systems it interacts with.

Mitigation & patch

Apply patches available from the manufacturer according to references — ECOVACS security advisory: https://www.ecovacs.com/global/userhelp/dsa20241217001. Until the update is installed, restrict device access to unknown/public networks and implement network segmentation.

Who is affected

Ecovacs Deebot X2 Omni (Firmware), Ecovacs Deebot X2 Combo (Firmware), Ecovacs Deebot X2S (Firmware) — specific versions indicated in manufacturer references (DSA20241217001)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Ecovacs Deebot T10

    HW
    Ecovacs
    all versions
  • Ecovacs Deebot T10 Firmware

    OS
    Ecovacs
    < 1.7.5
  • Ecovacs Deebot T10 Omni

    HW
    Ecovacs
    all versions
  • Ecovacs Deebot T10 Omni Firmware

    OS
    Ecovacs
    < 1.9.0
  • Ecovacs Deebot T10 Plus

    HW
    Ecovacs
    all versions
  • Ecovacs Deebot T10 Plus Firmware

    OS
    Ecovacs
    < 1.7.5
  • Ecovacs Deebot T10 Turbo

    HW
    Ecovacs
    all versions
  • Ecovacs Deebot T10 Turbo Firmware

    OS
    Ecovacs
    < 1.10.0
  • Ecovacs Deebot X1

    HW
    Ecovacs
    all versions
  • Ecovacs Deebot X1e Omni

    HW
    Ecovacs
    all versions
  • Ecovacs Deebot X1e Omni Firmware

    OS
    Ecovacs
    < 2.4.42
  • Ecovacs Deebot X1 Firmware

    OS
    Ecovacs
    < 1.7.3
  • Ecovacs Deebot X1 Omni

    HW
    Ecovacs
    all versions
  • Ecovacs Deebot X1 Omni Firmware

    OS
    Ecovacs
    < 2.4.41
  • Ecovacs Deebot X1 Plus

    HW
    Ecovacs
    all versions
  • Ecovacs Deebot X1 Plus Firmware

    OS
    Ecovacs
    < 1.7.3
  • Ecovacs Deebot X1 Pro Omni

    HW
    Ecovacs
    all versions
  • Ecovacs Deebot X1 Pro Omni Firmware

    OS
    Ecovacs
    < 2.4.41
  • Ecovacs Deebot X1s Pro

    HW
    Ecovacs
    all versions
  • Ecovacs Deebot X1s Pro Firmware

    OS
    Ecovacs
    < 2.5.31
  • Ecovacs Deebot X1s Pro Plus

    HW
    Ecovacs
    all versions
  • Ecovacs Deebot X1s Pro Plus Firmware

    OS
    Ecovacs
    < 1.23.0
  • Ecovacs Deebot X1 Turbo

    HW
    Ecovacs
    all versions
  • Ecovacs Deebot X1 Turbo Firmware

    OS
    Ecovacs
    < 2.4.41
  • Ecovacs Deebot X2 Combo

    HW
    Ecovacs
    all versions
  • Ecovacs Deebot X2 Combo Firmware

    OS
    Ecovacs
    < 1.81.10
  • Ecovacs Deebot X2 Omni

    HW
    Ecovacs
    all versions
  • Ecovacs Deebot X2 Omni Firmware

    OS
    Ecovacs
    < 1.76.6
  • Ecovacs Deebot X2 Pro

    HW
    Ecovacs
    all versions
  • Ecovacs Deebot X2 Pro Firmware

    OS
    Ecovacs
    < 1.76.6
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2025-30199HIGH7.5same product

ECOVACS vacuum robot base stations do not validate firmware updates, so malicious over-the-air updates can be ...

CVE-2024-11147HIGH7.0same product

ECOVACS robot lawnmowers and vacuums use a deterministic root password generated based on model and serial num...

CVE-2024-52331HIGH7.7same product

ECOVACS robot lawnmowers and vacuums use a deterministic symmetric key to decrypt firmware updates. An attacke...

CVE-2024-12078MEDIUM5.3same product

ECOVACS robot lawn mowers and vacuums use a shared, static secret key to encrypt BLE GATT messages. An unauthe...

CVE-2024-12079MEDIUM4.8same product

ECOVACS robot lawnmowers store the anti-theft PIN in cleartext on the device filesystem. An attacker can steal...